CVE-2022-43575: IBM Aspera Console cross-site scripting
IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238645.
Other sources
IBM Aspera Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43575?
CVE-2022-43575 is classified as a medium severity cross-site scripting vulnerability in IBM Aspera Console.
How do I fix CVE-2022-43575?
To fix CVE-2022-43575, upgrade IBM Aspera Console to version 3.4.2 or later, which includes patches for this vulnerability.
What are the affected versions of IBM Aspera Console for CVE-2022-43575?
Affected versions for CVE-2022-43575 include IBM Aspera Console versions 3.4.0 through 3.4.2 PL5.
What can attackers achieve through CVE-2022-43575?
Attackers can exploit CVE-2022-43575 to execute arbitrary JavaScript code in the web UI, potentially leading to credential disclosure.
Is CVE-2022-43575 a client-side or server-side vulnerability?
CVE-2022-43575 is primarily a client-side vulnerability due to its nature as a cross-site scripting flaw.