IBM Aspera Faspex
cpe:2.3:a:ibm:aspera_faspex:*:*:*:*:*:*:*
- >= 5.0.0, <= 5.0.12
A vulnerability exists in IBM Aspera Faspex versions 5.0.0 through 5.0.12, allowing authenticated users to access sensitive information or execute unauthorized actions on behalf of other users. This issue arises from client-side enforcement of server-side security, leading to improper protection of data.
Exploitation of this vulnerability could result in unauthorized actions being performed on behalf of another user or sensitive information being disclosed to an authenticated user.
Users are advised to upgrade to version 5.0.12.1, available from the IBM Container Registry. Instructions for upgrading can be found in the IBM Aspera Faspex documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.