PT-2023-5218 · Ibm · Ibm Aspera Faspex
CVE-2023-22870
·
Publicado
2023-08-29
·
Atualizado
2023-09-08
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Aspera Faspex version 5.0.5
Description
The issue is related to the lack of protection for transmitted data in the application. This could allow a remote attacker to obtain sensitive information using man-in-the-middle techniques.
Recommendations
For IBM Aspera Faspex version 5.0.5, consider implementing encryption for sensitive data transmission to prevent interception. As a temporary workaround, restrict access to sensitive information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aspera Faspex