IBM
IBM Aspera Console: vulnerabilidades y CVE
IBM Aspera Console tiene 18 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-13460 | Media (5.3) | 0.24% | — | 16 mar 2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy. |
| CVE-2025-13459 | Media (4.9) | 0.42% | — | 16 mar 2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow. |
| CVE-2025-13212 | Media (4.3) | 0.27% | — | 16 mar 2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency. |
| CVE-2025-13379 | Alta (8.6) | 0.37% | — | 5 feb 2026 | IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the… |
| CVE-2025-13925 | Media (4.9) | 0.33% | — | 20 ene 2026 | IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user. |
| CVE-2023-27272 | Alta (8.8) | 0.25% | — | 14 abr 2025 | IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system. |
| CVE-2022-43852 | Media (5.3) | 0.31% | — | 14 abr 2025 | IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system. |
| CVE-2022-43851 | Alta (7.5) | 0.22% | — | 14 abr 2025 | IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. |
| CVE-2022-43850 | Media (5.4) | 0.23% | — | 14 abr 2025 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… |
| CVE-2022-43847 | Media (5.4) | 0.23% | — | 14 abr 2025 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable… |
| CVE-2022-43840 | Media (4.3) | 0.30% | — | 14 abr 2025 | IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML… |
| CVE-2022-43845 | Alta (7.5) | 0.43% | — | 25 sept 2024 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain… |
| CVE-2021-38963 | Alta (8) | 0.64% | — | 25 sept 2024 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted… |
| CVE-2022-43841 | Baja (3.3) | 0.16% | — | 30 may 2024 | IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078. |
| CVE-2022-43575 | Media (5.4) | 0.25% | — | 30 may 2024 | IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2022-43384 | Media (5.4) | 0.25% | — | 30 may 2024 | IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2022-43842 | Crítica (9.1) | 0.53% | — | 23 feb 2024 | IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the… |
| CVE-2021-38927 | Media (6.1) | 0.34% | — | 25 dic 2023 | IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142