CVE-2025-33136
- EPSS 0.04%
- Veröffentlicht 22.05.2025 16:14:02
- Zuletzt bearbeitet 30.05.2025 01:19:40
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
CVE-2025-3423
- EPSS 0.04%
- Veröffentlicht 13.04.2025 11:56:15
- Zuletzt bearbeitet 18.07.2025 18:07:10
IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...
CVE-2023-37413
- EPSS 0.08%
- Veröffentlicht 29.01.2025 17:15:26
- Zuletzt bearbeitet 04.03.2025 21:43:48
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
CVE-2023-37412
- EPSS 0.05%
- Veröffentlicht 29.01.2025 17:15:26
- Zuletzt bearbeitet 04.03.2025 21:43:48
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
CVE-2023-37398
- EPSS 0.06%
- Veröffentlicht 29.01.2025 17:15:26
- Zuletzt bearbeitet 04.03.2025 21:43:48
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
CVE-2023-35907
- EPSS 0.06%
- Veröffentlicht 29.01.2025 17:15:26
- Zuletzt bearbeitet 04.03.2025 21:43:48
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
CVE-2023-37395
- EPSS 0.03%
- Veröffentlicht 11.12.2024 03:15:04
- Zuletzt bearbeitet 07.01.2025 21:10:50
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
CVE-2024-45098
- EPSS 0.04%
- Veröffentlicht 05.09.2024 16:15:08
- Zuletzt bearbeitet 06.09.2024 13:01:44
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
CVE-2024-45097
- EPSS 0.03%
- Veröffentlicht 05.09.2024 16:15:08
- Zuletzt bearbeitet 06.09.2024 12:51:59
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
CVE-2024-45096
- EPSS 0.14%
- Veröffentlicht 05.09.2024 16:15:07
- Zuletzt bearbeitet 06.09.2024 12:34:17
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.