CVE-2022-40744: IBM Aspera Faspex cross-site scripting
IBM Aspera Faspex 5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236441.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40744?
CVE-2022-40744 is considered a moderate severity vulnerability due to the potential for credential disclosure.
How do I fix CVE-2022-40744?
To fix CVE-2022-40744, upgrade IBM Aspera Faspex to version 5.0.7 or later.
What type of vulnerability is CVE-2022-40744?
CVE-2022-40744 is classified as a stored cross-site scripting (XSS) vulnerability.
What is affected by CVE-2022-40744?
CVE-2022-40744 affects IBM Aspera Faspex versions 5.0.6 and earlier.
What are the potential consequences of CVE-2022-40744?
The consequences of CVE-2022-40744 include the embedding of arbitrary JavaScript code that may lead to unauthorized actions in a trusted session.