CVE-2022-22497IBM Aspera Faspex vulnerability

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 47.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 24
Latest updateMay 25

Description

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/aspera_faspex4.4.1, 5.0.0+1
NVDibm/aspera_faspex4.4.1, 5.0.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-398v-5g69-w972: IBM Aspera Faspex 42022-05-25
CVEList
CVE-2022-22497: IBM Aspera Faspex 42022-05-24
CVE-2022-22497 — IBM Aspera Faspex vulnerability | cvebase