IBM Aspera是美国IBM公司的一套基于IBM FASP协议构建的快速文件传输和流解决方案。 多款IBM产品中存在注入漏洞。攻击者可利用该漏洞在SOAP API中执行命令。以下产品及版本受到影响:IBM Aspera High-Speed Transfer Server 3.9.3及之前版本;High-Speed Transfer Endpoint 3.9.3及之前版本;Proxy Server 1.4.3及之前版本;Transfer Cluster Manager 1.3.1版本和3.9.3及之前
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Aspera Streaming | 3.9.3 | - |
|
| IBM | Aspera High-Speed Transfer Endpoint | 3.9.3 | - |
|
| IBM | Aspera High-Speed Transfer Server for Cloud Pak for Integration (CP4I) | 3.9.10 | - |
|
| IBM | Aspera Server On Demand | 3.7.4 | - |
|
| IBM | Aspera Faspex On Demand | 3.7.4 | - |
|
| IBM | Aspera Proxy Server | 1.4.3 | - |
|
| IBM | Aspera Application Platform On Demand | 3.7.4 | - |
|
| IBM | Aspera Shares On Demand | 3.7.4 | - |
|
| IBM | Aspera High-Speed Transfer Server | 3.9.3 | - |
|
| IBM | Aspera Transfer Cluster Manager | 1.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-4576 | IBM QRadar Network Packet Capture 安全漏洞 | |
| CVE-2020-4433 | 多款IBM产品缓冲区错误漏洞 | |
| CVE-2020-4434 | 多款IBM产品缓冲区错误漏洞 | |
| CVE-2020-4435 | IBM Aspera 缓冲区错误漏洞 | |
| CVE-2020-4436 | 多款IBM产品缓冲区错误漏洞 |
No comments yet