Vulnerabilities > IBM > Aspera Faspex > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-09-08 CVE-2022-22409 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration.
network
low complexity
ibm
5.3
2023-09-08 CVE-2022-22405 Missing Encryption of Sensitive Data vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-311
5.9
2023-09-08 CVE-2023-24965 Exposure of Resource to Wrong Sphere vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
network
low complexity
ibm CWE-668
5.3
2023-09-05 CVE-2023-22870 Cleartext Transmission of Sensitive Information vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques.
network
high complexity
ibm CWE-319
5.9
2023-03-21 CVE-2023-27873 Unspecified vulnerability in IBM Aspera Faspex 4.4.1/4.4.2
IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input.
network
low complexity
ibm
6.5
2023-02-17 CVE-2023-22868 Unspecified vulnerability in IBM Aspera Faspex 4.4.1
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting.
network
low complexity
ibm
5.4