cbcvebase.

Ibm Aspera Faspex vulnerabilities

46 known vulnerabilities affecting ibm/aspera_faspex.

Total CVEs
46
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH12MEDIUM29LOW2

Vulnerabilities

Page 2 of 3
CVE-2022-22399P4MEDIUMCVSS 6.5v5.0.0v5.0.1+1 more2024-03-05
CVE-2022-22399 [MEDIUM] CWE-644 CVE-2022-22399: IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validat IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 222562.
nvd
CVE-2025-33138P4MEDIUMCVSS 6.1≥ 5.0.0, < 5.0.12.1≥ 5.0.0, ≤ 5.0.122025-05-22
CVE-2025-33138 [MEDIUM] CWE-80 CVE-2025-33138: IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inje IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2022-22405P4MEDIUMCVSS 5.9≤ 5.0.5v5.0.52023-09-08
CVE-2022-22405 [MEDIUM] CWE-311 CVE-2022-22405: IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 222576.
nvd
CVE-2025-36230P4MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.14.22025-12-26
CVE-2025-36230 [MEDIUM] CWE-80 CVE-2025-36230: IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2023-22870P4MEDIUMCVSS 5.9≤ 5.0.5v5.0.52023-09-05
CVE-2023-22870 [MEDIUM] CWE-319 CVE-2023-22870: IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an a IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 244121.
nvd
CVE-2023-37401P4MEDIUMCVSS 5.3≥ 5.0.0, < 5.0.14≥ 5.0.0, ≤ 5.0.13.12025-10-09
CVE-2023-37401 [MEDIUM] CWE-942 CVE-2023-37401: IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.
nvd
CVE-2025-36226P4MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.152026-03-10
CVE-2025-36226 [MEDIUM] CWE-79 CVE-2025-36226: IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-36227P4MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.152026-03-10
CVE-2025-36227 [MEDIUM] CWE-644 CVE-2025-36227: IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by imprope IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
nvd
CVE-2023-24965P4MEDIUMCVSS 5.3≤ 5.0.5v5.0.52023-09-08
CVE-2023-24965 [MEDIUM] CWE-668 CVE-2023-24965: IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unau IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713.
nvd
CVE-2022-22409P4MEDIUMCVSS 5.3≤ 5.0.5v5.0.52023-09-08
CVE-2022-22409 [MEDIUM] CWE-200 CVE-2022-22409: IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592.
nvd
CVE-2025-3423P4MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.12≥ 5.0.0, ≤ 5.0.112025-04-13
CVE-2025-3423 [MEDIUM] CWE-79 CVE-2025-3423: IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability all IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-37413P4MEDIUMCVSS 5.3≥ 5.0.0, ≤ 5.0.102025-01-29
CVE-2023-37413 [MEDIUM] CWE-204 CVE-2023-37413: IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an obser IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
nvd
CVE-2023-22869P4MEDIUMCVSS 5.5≥ 5.0.0, < 5.0.8≥ 5.0.0, ≤ 5.0.72024-04-19
CVE-2023-22869 [MEDIUM] CWE-532 CVE-2023-22869: IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that cou IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.
nvd
CVE-2022-22402P4MEDIUMCVSS 5.4≤ 5.0.5v5.0.52023-09-08
CVE-2022-22402 [MEDIUM] CWE-79 CVE-2022-22402: IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to em IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 222571.
nvd
CVE-2022-40744P4MEDIUMCVSS 5.4fixed in 5.0.7v5.0.62024-02-02
CVE-2022-40744 [MEDIUM] CWE-79 CVE-2022-40744: IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows user IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236441.
nvd
CVE-2023-37411P4MEDIUMCVSS 5.4≥ 5.0.0, ≤ 5.0.62024-05-28
CVE-2023-37411 [MEDIUM] CWE-79 CVE-2023-37411: IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allo IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260139.
nvd
CVE-2023-22868P4MEDIUMCVSS 5.4≤ 4.4.1v4.4.12023-02-17
CVE-2023-22868 [MEDIUM] CWE-79 CVE-2023-22868: IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to em IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 244117.
nvd
CVE-2023-37412P4MEDIUMCVSS 4.9≥ 5.0.0, ≤ 5.0.102025-01-29
CVE-2023-37412 [MEDIUM] CWE-250 CVE-2023-37412: IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
nvd
CVE-2022-40745P4MEDIUMCVSS 5.5≥ 5.0.0, ≤ 5.0.72024-04-19
CVE-2022-40745 [MEDIUM] CWE-326 CVE-2022-40745: IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due t IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.
nvd
CVE-2023-37396P4MEDIUMCVSS 5.5≥ 5.0.0, < 5.0.8≥ 5.0.0, ≤ 5.0.72024-04-19
CVE-2023-37396 [MEDIUM] CWE-327 CVE-2023-37396: IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due t IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.
nvd
Ibm Aspera Faspex vulnerabilities | cvebase