VYPR

Aspera Faspex

by IBM

CVEs (49)

  • CVE-2023-37411MedMay 28, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…

  • CVE-2022-40744MedFeb 2, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…

  • CVE-2023-37412MedJan 29, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.

  • CVE-2025-36225MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

  • CVE-2025-36228LowDec 26, 2025
    risk 0.25cvss 3.8epss 0.00

    IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.

  • CVE-2023-37397LowApr 19, 2024
    risk 0.23cvss 3.6epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.

  • CVE-2025-36229LowDec 26, 2025
    risk 0.20cvss 3.1epss 0.00

    IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.

  • CVE-2023-37395LowDec 11, 2024
    risk 0.16cvss 2.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.

  • CVE-2023-37396LowApr 19, 2024
    risk 0.16cvss 2.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.

Page 3 of 3