CVE-2022-22391: Medium severity IBM Aspera High-Speed Transfer Endpoint vulnerability
IBM Aspera could allow an authenticated user to obtain information from non sensitive operating system files that they should not have access to.
Other sources
IBM Aspera High-Speed Transfer 4.3.1 and earlier could allow an authenticated user to obtain information from non sensitive operating system files that they should not have access to. IBM X-Force ID: 222059.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22391?
CVE-2022-22391 is rated as a high-severity vulnerability.
How do I fix CVE-2022-22391?
To fix CVE-2022-22391, upgrade IBM Aspera High-Speed Transfer to version 4.3.2 or later.
Who is affected by CVE-2022-22391?
CVE-2022-22391 affects IBM Aspera High-Speed Transfer Endpoint and Server versions 4.3.1 and earlier.
What type of vulnerability is CVE-2022-22391?
CVE-2022-22391 is an information disclosure vulnerability.
Can an authenticated user exploit CVE-2022-22391?
Yes, an authenticated user can exploit CVE-2022-22391 to access sensitive operating system files.