IBM Aspera Faspex Weak Password Requirement Vulnerability

Vulnerability

A vulnerability exists in IBM Aspera Faspex versions 5.0.0 to 5.0.10, where the application does not enforce strong password requirements by default. This oversight makes it easier for attackers to compromise user accounts.

Impact

Exploitation of this vulnerability could lead to unauthorized account access, allowing attackers to compromise user accounts more easily.

Remediation

Users are advised to upgrade to IBM Aspera Faspex version 5.0.11, available through the IBM Support Fix Central.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.