All 41 CVE vulnerabilities found in Aspera Faspex, with AI-generated Chinese analysis, references, and POCs.
This page is a vulnerability aggregation resource for the Aspera Faspex product, specifically focusing on Common Weakness Enumeration (CWE) classifications and associated security advisories. It collects documented security vulnerabilities affecting Aspera Faspex versions, covering a comprehensive time range from initial release notes through the most recent patches and updates. Here, users can discover detailed insights by tracking the vendor's historical security advisories to understand the context and severity of reported issues. Visitors can also analyze specific weakness classes to see how they manifest within the Faspex architecture, aiding in targeted risk assessment and mitigation planning. Furthermore, the page provides a chronological history of vulnerabilities for the product, allowing administrators and security professionals to review past incidents, evaluate the effectiveness of previous remediation efforts, and identify potential patterns or recurring issues. This aggregated data serves as a centralized reference for understanding the security posture of Aspera Faspex over time. By consolidating disparate sources into a single view, the page facilitates more efficient vulnerability management and informed decision-making for teams responsible for securing file transfer and exchange environments. The content is structured to support both quick lookups for specific concerns and deeper analysis of broader security trends. Users can navigate through entries to gain a holistic view of the product's evolving threat landscape without needing to search multiple external databases. This approach streamlines the process of staying compliant with security standards and maintaining robust defense mechanisms against known exploits. The information provided is intended to support technical reviews, audit preparations, and proactive security hygiene within organizational IT infrastructure.
Vendor: IBM
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-24965 | IBM Aspera Faspex improper access control | 5.8 | Medium | 2023-09-08 |
| CVE-2022-22405 | IBM Aspera Faspex information disclosure CWE-311 | 5.9 | Medium | 2023-09-08 |
| CVE-2023-35906 | IBM Aspera Faspex security bypass CWE-291 | 5.3 | Medium | 2023-09-05 |
| CVE-2023-22870 | IBM Aspera Faspex information disclosure CWE-319 | 5.9 | Medium | 2023-09-05 |
| CVE-2023-27873 | IBM Aspera Faspex information disclosure | 6.5 | Medium | 2023-03-21 |
| CVE-2023-27874 | IBM Aspera Faspex XML external entity injection CWE-611 | 9.9 | Critical | 2023-03-21 |
| CVE-2023-27871 | IBM Aspera Faspex information disclosure | 7.5 | High | 2023-03-21 |
| CVE-2023-27875 | IBM Aspera Faspex improper access controls | 7.5 | High | 2023-03-16 |
| CVE-2023-22868 | IBM Aspera Faspex cross-site scripting CWE-79 | 5.4 | Medium | 2023-02-17 |
| CVE-2022-47986 | IBM Aspera Faspex code execution CWE-502 | 9.8 | Critical | 2023-02-17 |
| CVE-2022-22497 | IBM Aspera 安全漏洞 | 7.5 | - | 2022-05-24 |
All 41 known CVE vulnerabilities affecting Aspera Faspex with full Chinese analysis, references, and POCs where available.