cbcvebase.
CVE-2024-38315
published 2024-09-16

CVE-2024-38315: IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user…

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.23%
13.4th percentile
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

Affected

3 ranges
VendorProductVersion rangeFixed in
ibmaspera_shares
ibmaspera_shares1.0 – 1.10.0 PL3
ibmaspera_shares>= 1.0.0 < 1.10.01.10.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.