VYPR

Aspera Faspex

by IBM

CVEs (25)

  • CVE-2023-37411MedMay 28, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…

  • CVE-2022-40744MedFeb 2, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…

  • CVE-2025-36225MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

  • CVE-2023-37397LowApr 19, 2024
    risk 0.23cvss 3.6epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.

  • CVE-2023-37396LowApr 19, 2024
    risk 0.16cvss 2.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.

Page 2 of 2