IBM Aspera Faspex是美国国际商业机器(IBM)公司的一种用于快速的全球个人对个人文件交付和协作的解决方案。 IBM Aspera Faspex 5 5.0.14.1及之前版本存在安全漏洞,该漏洞源于远程攻击者可注入恶意HTML代码,可能导致在受害者浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Aspera Faspex 5 | 5.0.0 ~ 5.0.14.1 |
cpe:2.3:a:ibm:aspera_faspex_5:5.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-13915 | 9.8 CRITICAL | Authentication bypass in IBM API Connect |
| CVE-2025-12771 | 7.8 HIGH | IBM Concert Software Improper Restriction of Operations within the Bounds of a Memory Buff |
| CVE-2025-64645 | 7.7 HIGH | Multiple Vulnerabilities in IBM Concert Software. |
| CVE-2025-36192 | 6.7 MEDIUM | Missing Authorization with the DS8900F and DS8A00 Hardware Management Console |
| CVE-2025-1721 | 5.9 MEDIUM | BM Concert Software Improper Clearing of Heap Memory Before Release. |
| CVE-2025-14687 | 4.3 MEDIUM | Client-Side Enforcement of Server-Side Security in IBM Db2 Intelligence Center |
| CVE-2025-36228 | 3.8 LOW | Incorrect Execution-Assigned Permissions in IBM Aspera Faspex |
| CVE-2025-36229 | 3.1 LOW | Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera F |
No comments yet