Vulnerabilities
Vulnerable Software
Ibm:  >> Aspera Faspex  >> 4.4.1  Security Vulnerabilities
IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654.
CVSS Score
6.5
EPSS Score
0.0
Published
2023-03-21
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.
CVSS Score
9.9
EPSS Score
0.001
Published
2023-03-21
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 244117.
CVSS Score
5.4
EPSS Score
0.002
Published
2023-02-17
CVE-2022-47986
Known exploited
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
CVSS Score
9.8
EPSS Score
0.943
Published
2023-02-17
IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-05-24


Contact Us

Shodan ® - All rights reserved