PT-2022-6902 · Ibm · Ibm Aspera Faspex

Published

2022-01-03

·

Updated

2023-09-13

·

CVE-2022-22409

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Aspera Faspex version 5.0.5
Description The issue is related to an insecure configuration in the application, which may allow a remote attacker to gather sensitive information about the web application. This is due to insufficient protection of service data.
Recommendations For IBM Aspera Faspex version 5.0.5, consider reconfiguring the application to ensure proper protection of service data until a patch is available. As a temporary workaround, restrict access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-05460
CVE-2022-22409

Affected Products

Ibm Aspera Faspex