First published: Tue Sep 24 2024(Updated: )
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
IBM Aspera Console | >=3.4.0<3.4.5 | |
Any of | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43845 is rated as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2022-43845, ensure that the HTTPOnly flag is set on cookies in IBM Aspera Console versions 3.4.0 to 3.4.4.
CVE-2022-43845 affects users of IBM Aspera Console versions 3.4.0 through 3.4.4.
CVE-2022-43845 could allow remote attackers to obtain sensitive information stored in cookies.
Currently, applying the recommended security patch is the best approach, as there are no widely reported workarounds for CVE-2022-43845.