CVE-2022-22402: IBM Aspera Faspex cross-site scripting
Published Aug 29, 2023
·Updated
IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 222571.
Affected Software
3 affected components
IBM Aspera Faspex<=5.0.5 and prior
IBM Aspera Faspex<=5.0.5
Linux Linux Kernel
Remediation
Patch Available
Event History
Aug 29, 2023
CVE Published
via IBM·12:00 AM
Sep 8, 2023
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22402.
2
What is the title of this vulnerability?
The title of this vulnerability is IBM Aspera Faspex 5 is vulnerable to cross-site scripting.
3
What is the CVE severity score for this vulnerability?
The CVE severity score for this vulnerability is 5.4 (medium).
4
How can this vulnerability be exploited?
This vulnerability can be exploited by embedding arbitrary JavaScript code in the Web UI.
5
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. Please refer to the vendor's support page for instructions.