Vulnerabilities > IBM > Aspera Faspex > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-29 CVE-2023-37412 Execution with Unnecessary Privileges vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
network
low complexity
ibm CWE-250
4.9
2025-01-29 CVE-2023-37413 Response Discrepancy Information Exposure vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
network
low complexity
ibm CWE-204
5.3
2024-09-05 CVE-2024-45096 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.
network
low complexity
ibm
6.5
2024-05-28 CVE-2023-37411 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting.
network
low complexity
ibm
5.4
2024-04-19 CVE-2022-40745 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security.
local
low complexity
ibm
5.5
2024-04-19 CVE-2023-27279 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting.
network
low complexity
ibm
6.5
2024-04-19 CVE-2023-37397 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data.
local
low complexity
ibm
4.4
2024-04-19 CVE-2023-22869 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm
5.5
2024-04-19 CVE-2023-37396 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
local
low complexity
ibm
5.5
2024-03-05 CVE-2022-22399 Improper Encoding or Escaping of Output vulnerability in IBM Aspera Faspex 5.0.0/5.0.1
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-116
6.5