IBM
IBM Aspera Faspex: vulnerabilidades y CVE
IBM Aspera Faspex tiene 49 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE49
Últimos 12 meses11
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-47986 | Crítica (9.8) | 100% | ⚠ Explotación activa | 17 feb 2023 | IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-14996 | Alta (8.2) | 0.34% | — | 28 jul 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. |
| CVE-2026-14959 | Alta (7.2) | 1.6% | — | 28 jul 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. |
| CVE-2026-14958 | Alta (7.2) | 0.82% | — | 28 jul 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. |
| CVE-2025-36227 | Media (5.4) | 0.21% | — | 10 mar 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the… |
| CVE-2025-36226 | Media (5.4) | 0.21% | — | 10 mar 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2025-36230 | Media (5.4) | 0.20% | — | 26 dic 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security… |
| CVE-2025-36229 | Media (4.3) | 0.24% | — | 26 dic 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers. |
| CVE-2025-36228 | Baja (3.8) | 0.22% | — | 26 dic 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse. |
| CVE-2025-36225 | Media (4.3) | 0.23% | — | 9 oct 2025 | IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data. |
| CVE-2025-36171 | Media (4.9) | 0.32% | — | 9 oct 2025 | IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption. |
| CVE-2023-37401 | Media (5.3) | 0.22% | — | 9 oct 2025 | IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. |
| CVE-2025-36040 | Media (6.5) | 0.21% | — | 31 jul 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms. |
| CVE-2025-36039 | Media (6.5) | 0.26% | — | 31 jul 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms, |
| CVE-2025-33138 | Media (6.1) | 0.26% | — | 22 may 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of… |
| CVE-2025-33137 | Alta (8.8) | 0.34% | — | 22 may 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security. |
| CVE-2025-33136 | Alta (8.8) | 0.34% | — | 22 may 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data. |
| CVE-2025-3423 | Media (5.4) | 0.28% | — | 13 abr 2025 | IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2023-37413 | Media (5.3) | 0.30% | — | 29 ene 2025 | IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy. |
| CVE-2023-37412 | Media (4.9) | 0.27% | — | 29 ene 2025 | IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls. |
| CVE-2023-37398 | Crítica (9.8) | 0.33% | — | 29 ene 2025 | IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. |
| CVE-2023-35907 | Crítica (9.8) | 0.33% | — | 29 ene 2025 | IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. |
| CVE-2023-37395 | Baja (3.3) | 0.06% | — | 11 dic 2024 | IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. |
| CVE-2024-45098 | Alta (8.1) | 0.35% | — | 5 sept 2024 | IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification. |
| CVE-2024-45097 | Alta (7.1) | 0.31% | — | 5 sept 2024 | IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification. |
| CVE-2024-45096 | Media (6.5) | 0.37% | — | 5 sept 2024 | IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing. |
| CVE-2023-37411 | Media (5.4) | 0.25% | — | 28 may 2024 | IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… |
| CVE-2023-37397 | Media (4.4) | 0.08% | — | 19 abr 2024 | IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672. |
| CVE-2023-27279 | Media (6.5) | 0.71% | — | 19 abr 2024 | IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533. |
| CVE-2022-40745 | Media (5.5) | 0.14% | — | 19 abr 2024 | IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452. |
| CVE-2023-37396 | Media (5.5) | 0.08% | — | 19 abr 2024 | IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142