Lucene search

K
nvd[email protected]NVD:CVE-2024-38315
HistorySep 16, 2024 - 3:15 p.m.

CVE-2024-38315

2024-09-1615:15:16
CWE-613
web.nvd.nist.gov
ibm aspera
shares
session
authentication
vulnerability

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0

Percentile

14.1%

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

Affected configurations

Nvd
Node
ibmaspera_sharesRange1.0.01.10.0
OR
ibmaspera_sharesMatch1.10.0-
OR
ibmaspera_sharesMatch1.10.0patch_level1
OR
ibmaspera_sharesMatch1.10.0patch_level2
OR
ibmaspera_sharesMatch1.10.0patch_level3
VendorProductVersionCPE
ibmaspera_shares*cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
ibmaspera_shares1.10.0cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:*
ibmaspera_shares1.10.0cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:*
ibmaspera_shares1.10.0cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:*
ibmaspera_shares1.10.0cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0

Percentile

14.1%

Related for NVD:CVE-2024-38315