CVE Vulnerabilities for "product:aspera_faspex"

Showing 1-10 of 46 CVEs (filtered from 316,527 total)

IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

MEDIUM 4.3
EPSS 0.0%
10/9/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.

MEDIUM 4.9
EPSS 0.1%
10/9/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.

MEDIUM 5.3
EPSS 0.0%
10/9/2025
2023

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

MEDIUM 6.5
EPSS 0.0%
7/31/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,

MEDIUM 6.5
EPSS 0.1%
7/31/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

MEDIUM 5.4
EPSS 0.0%
5/22/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.

HIGH 7.1
EPSS 0.0%
5/22/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

HIGH 7.1
EPSS 0.0%
5/22/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

MEDIUM 5.4
EPSS 0.0%
4/13/2025
2025

IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

MEDIUM 5.3
EPSS 0.1%
1/29/2025
2023
Page 1 of 2