5.3

CVE-2024-56473

IBM Aspera Shares Data Manipulation

IBM Aspera Shares 1.9.0 through 1.10.0 PL6  could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Aspera Shares Version >= 1.9.0 < 1.10.0
Ibm ≫ Aspera Shares Version 1.10.0 Update -
Ibm ≫ Aspera Shares Version 1.10.0 Update patch_level1
Ibm ≫ Aspera Shares Version 1.10.0 Update patch_level2
Ibm ≫ Aspera Shares Version 1.10.0 Update patch_level3
Ibm ≫ Aspera Shares Version 1.10.0 Update patch_level4
Ibm ≫ Aspera Shares Version 1.10.0 Update patch_level5
Ibm ≫ Aspera Shares Version 1.10.0 Update patch_level6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.199
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
IBM 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

CWE-117 Improper Output Neutralization for Logs

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

https://www.ibm.com/support/pages/node/7182490
Vendor Advisory