CVE-2022-40745: IBM Aspera Faspex information disclosure
IBM Aspera Faspex 5 could allow a local user to obtain sensitive information due to weaker than expected security.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40745?
CVE-2022-40745 has been assessed to pose a medium severity risk due to its potential to expose sensitive information.
How do I fix CVE-2022-40745?
To mitigate CVE-2022-40745, it is recommended to upgrade IBM Aspera Faspex to a version later than 5.0.7, which addresses this vulnerability.
Who is affected by CVE-2022-40745?
CVE-2022-40745 affects local users of IBM Aspera Faspex versions 5.0.0 through 5.0.7.
What type of vulnerability is CVE-2022-40745?
CVE-2022-40745 is classified as an information disclosure vulnerability due to weaker security measures.
Can CVE-2022-40745 be exploited remotely?
CVE-2022-40745 requires local access, which makes remote exploitation highly unlikely.