CVE-2022-22405: IBM Aspera Faspex information disclosure
Published Aug 29, 2023
·Updated
IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 222576.
Affected Software
3 affected components
IBM Aspera Faspex<=5.0.5 and prior
IBM Aspera Faspex<=5.0.5
Linux Linux Kernel
Remediation
Patch Available
Event History
Aug 29, 2023
CVE Published
via IBM·12:00 AM
Sep 8, 2023
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22405.
2
What is the title of the vulnerability?
The title of the vulnerability is 'IBM Aspera Faspex 5 could allow a remote attacker to obtain sensitive information caused by the fail…'
3
What is the severity of CVE-2022-22405?
The severity of CVE-2022-22405 is medium with a severity value of 5.9.
4
What is affected by CVE-2022-22405?
IBM Aspera Faspex 5.0.5 and prior versions are affected by CVE-2022-22405.
5
How can an attacker exploit CVE-2022-22405?
An attacker can exploit CVE-2022-22405 by using man-in-the-middle techniques to obtain sensitive information.