CVE-2025-13212
- EPSS 0.05%
- Veröffentlicht 13.03.2026 19:54:10
- Zuletzt bearbeitet 17.03.2026 15:49:03
IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
CVE-2025-13459
- EPSS 0.05%
- Veröffentlicht 13.03.2026 19:54:05
- Zuletzt bearbeitet 17.03.2026 15:49:45
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
CVE-2025-13460
- EPSS 0.03%
- Veröffentlicht 13.03.2026 19:54:04
- Zuletzt bearbeitet 17.03.2026 15:50:01
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.
CVE-2025-13379
- EPSS 0.05%
- Veröffentlicht 05.02.2026 13:30:04
- Zuletzt bearbeitet 12.02.2026 19:08:57
IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2025-13925
- EPSS 0.04%
- Veröffentlicht 20.01.2026 15:16:13
- Zuletzt bearbeitet 30.01.2026 13:55:23
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.
CVE-2022-43850
- EPSS 0.3%
- Veröffentlicht 14.04.2025 20:44:59
- Zuletzt bearbeitet 17.07.2025 18:58:04
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit...
CVE-2022-43840
- EPSS 0.24%
- Veröffentlicht 14.04.2025 20:43:28
- Zuletzt bearbeitet 24.07.2025 18:15:24
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
CVE-2022-43851
- EPSS 0.15%
- Veröffentlicht 14.04.2025 20:39:56
- Zuletzt bearbeitet 17.07.2025 18:56:28
IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2023-27272
- EPSS 0.18%
- Veröffentlicht 14.04.2025 20:38:20
- Zuletzt bearbeitet 17.07.2025 18:51:51
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
CVE-2022-43852
- EPSS 0.24%
- Veröffentlicht 14.04.2025 20:33:58
- Zuletzt bearbeitet 17.07.2025 18:53:41
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.