QID 379457
Date Published: 2024-03-18
QID 379457: IBM Aspera Faspex Hypertext Transfer Protocol (HTTP) Header Injection Vulnerability (6618959)
Faspex is a centralized transfer solution that enables users to exchange files with each other using an email-like workflow.
CVE-2022-22399: IBM Aspera Faspex 5 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Affected platform: Linux
Affected Versions: IBM Aspera Faspex 5.0.0
IBM Aspera Faspex 5.0.1
QID Detection Logic (Authenticated):
(Linux)This QID uses package based query in case of Linux.
QID Detection Logic (Unauthenticated):
This QID send a GET request to aspera/faspex page to check the vulnerable version.
Successful exploitation of this vulnerability could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
CVEs related to QID 379457
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6618959 |
|