IBM Aspera是美国国际商业机器(IBM)公司的一套基于IBM FASP协议构建的快速文件传输和流解决方案。 IBM Aspera Faspex 5.0.0 和 5.0.1版本存在安全漏洞,该漏洞源于HOST 标头输入验证不正确,允许攻击者对易受攻击的系统进行各种攻击,包括跨站脚本、缓存中毒或会话劫持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Aspera Faspex | 5.0.0, 5.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-35899 | 7.0 HIGH | IBM Cloud Pak for Automation CSV injection |
| CVE-2024-22352 | 6.5 MEDIUM | IBM InfoSphere Information Server information disclosure |
| CVE-2023-25681 | 5.3 MEDIUM | IBM Spectrum Virtualize security bypass |
| CVE-2023-26282 | 4.2 MEDIUM | IBM Watson CP4D Data Stores file modificiation |
No comments yet