Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm aspera faspex vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2022-22409
IBM Aspera Faspex 5.0.5 could allow a remote malicious user to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592.
Ibm Aspera Faspex
7.5
CVSSv3
CVE-2023-30995
IBM Aspera Faspex 4.0 up to and including 4.4.2 and 5.0 up to and including 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268.
Ibm Aspera Faspex
5.4
CVSSv3
CVE-2022-22402
IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 222571.
Ibm Aspera Faspex
5.9
CVSSv3
CVE-2022-22405
IBM Aspera Faspex 5.0.5 could allow a remote malicious user to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. I...
Ibm Aspera Faspex
NA
CVE-2023-37400
IBM Aspera Faspex 5.0.0 up to and including 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.
NA
CVE-2023-22869
IBM Aspera Faspex 5.0.0 up to and including 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.
NA
CVE-2023-37396
IBM Aspera Faspex 5.0.0 up to and including 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.
NA
CVE-2022-22399
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an malicious user to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or se...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
firmware
CVE-2023-52866
CVE-2024-4367
CVE-2024-1721
CVE-2023-34992
XML injection
CVE-2023-52817
SQL
CVE-2023-52855
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3