First published: Wed May 29 2024(Updated: )
IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Console | <=3.4.0 - 3.4.2 PL9 | |
IBM Aspera Console | >=3.4.0<=3.4.2 | |
IBM Aspera Console | =3.4.2-patch_level_1 | |
IBM Aspera Console | =3.4.2-patch_level_2 | |
IBM Aspera Console | =3.4.2-patch_level_3 | |
IBM Aspera Console | =3.4.2-patch_level_4 | |
IBM Aspera Console | =3.4.2-patch_level_5 | |
IBM Aspera Console | =3.4.2-patch_level_6 | |
IBM Aspera Console | =3.4.2-patch_level_7 | |
IBM Aspera Console | =3.4.2-patch_level_8 | |
IBM Aspera Console | =3.4.2-patch_level_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43841 is moderate due to the potential for information disclosure.
To fix CVE-2022-43841, you should upgrade IBM Aspera Console to version 3.4.2 PL10 or later.
IBM Aspera Console versions 3.4.0 through 3.4.2 PL9 are affected by CVE-2022-43841.
CVE-2022-43841 is classified as an information disclosure vulnerability.
CVE-2022-43841 requires local access to exploit the information disclosure vulnerability.