Lucene search

K
cvelistIbmCVELIST:CVE-2023-22869
HistoryApr 19, 2024 - 3:48 p.m.

CVE-2023-22869 IBM Aspera Faspex information disclosure

2024-04-1915:48:02
CWE-532
ibm
www.cve.org
2
ibm
aspera faspex
information disclosure

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0

Percentile

9.0%

IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Aspera Faspex",
    "vendor": "IBM",
    "versions": [
      {
        "lessThanOrEqual": "5.0.7",
        "status": "affected",
        "version": "5.0.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2023-22869