QID 379347
Date Published: 2024-02-12
QID 379347: IBM Aspera Faspex Cross-Site Scripting (XSS) Vulnerability (7111778)
Faspex is a centralized transfer solution that enables users to exchange files with each other using an email-like workflow.
CVE-2022-40744: IBM Aspera Faspex is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected platform: Linux
Affected Versions: IBM Aspera Faspex 5 prior to version 5.0.7
QID Detection Logic (Authenticated):
(Linux)This QID uses package based query in case of Linux.
QID Detection Logic (Unauthenticated):
This QID send a GET request to aspera/faspex page to check the vulnerable version.
Successful exploitation of this vulnerability can potentially lead to credentials disclosure within a trusted session.
- CVE-2022-40744 -
www.ibm.com/support/pages/node/7111778
CVEs related to QID 379347
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7111778 |
|