Ibm

Aspera Faspex

38 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Published 05.09.2023 01:15:07
  • Last modified 21.11.2024 07:45:33

IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 244121.

  • EPSS 0.14%
  • Published 21.03.2023 15:15:12
  • Last modified 21.11.2024 07:53:37

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.

  • EPSS 0.05%
  • Published 21.03.2023 15:15:12
  • Last modified 21.11.2024 07:53:36

IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654.

  • EPSS 0.05%
  • Published 21.03.2023 15:15:12
  • Last modified 25.02.2025 20:15:32

IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613.

  • EPSS 0.04%
  • Published 16.03.2023 13:15:10
  • Last modified 26.02.2025 15:15:19

IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.

  • EPSS 0.19%
  • Published 17.02.2023 17:15:11
  • Last modified 21.11.2024 07:45:33

IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se...

Warning
  • EPSS 94.35%
  • Published 17.02.2023 16:15:10
  • Last modified 06.03.2025 19:48:51

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerabi...

  • EPSS 0.29%
  • Published 24.05.2022 22:15:10
  • Last modified 21.11.2024 06:46:54

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.