CVE-2022-22409: IBM Aspera Faspex information disclosure
Published Aug 29, 2023
·Updated
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592.
Affected Software
3 affected components
IBM Aspera Faspex<=5.0.5 and prior
IBM Aspera Faspex<=5.0.5
Linux Linux Kernel
Remediation
Patch Available
Event History
Aug 29, 2023
CVE Published
via IBM·12:00 AM
Sep 8, 2023
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the insecure configuration in IBM Aspera Faspex 5?
The vulnerability ID of the insecure configuration in IBM Aspera Faspex 5 is CVE-2022-22409.
2
What is the severity of CVE-2022-22409?
The severity of CVE-2022-22409 is medium with a CVSS score of 5.3.
3
How can a remote attacker exploit CVE-2022-22409?
A remote attacker can exploit CVE-2022-22409 to gather sensitive information about the web application.
4
What is the affected version of IBM Aspera Faspex?
IBM Aspera Faspex version 5.0.5 and prior are affected by this vulnerability.
5
Is the Linux Kernel vulnerable to CVE-2022-22409?
No, the Linux Kernel is not vulnerable to CVE-2022-22409.