Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-11695
HistoryFeb 21, 2023 - 12:00 a.m.

IBM Aspera Faspex Cross-Site Scripting Vulnerability

2023-02-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
20
ibm
aspera
faspex
cross-site scripting
vulnerability
version 4.4.1
javascript code
web ui
credential disclosure
trusted sessions
fasp protocol-based
file transfer
streaming solution
international business machines

EPSS

0.001

Percentile

20.2%

IBM Aspera is an IBM FASP protocol-based fast file transfer and streaming solution from International Business Machines (IBM). IBM Aspera Faspex version 4.4.1 contains a cross-site scripting vulnerability, which stems from a cross-site scripting vulnerability that could be exploited by an attacker to embed arbitrary JavaScript code in the Web UI which could lead to credential disclosure in trusted sessions.

EPSS

0.001

Percentile

20.2%

Related for CNVD-2023-11695