CVE-2022-43847: IBM Aspera Console HTTP header injection
Published Apr 14, 2025
·Updated
IBM Aspera Console 3.4.0 through 3.4.4
is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Affected Software
4 affected components
IBM Aspera Console>=3.4.0<=3.4.4
All of the following
IBM Aspera Console>=3.4.0<3.4.5
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Apr 14, 2025
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43847?
CVE-2022-43847 has been rated as a medium severity vulnerability.
2
What type of information can be compromised by CVE-2022-43847?
CVE-2022-43847 can allow attackers to access sensitive information stored in cookies.
3
How do I fix CVE-2022-43847?
To fix CVE-2022-43847, ensure the HTTPOnly flag is set for cookies in IBM Aspera Console.
4
Which versions of IBM Aspera Console are affected by CVE-2022-43847?
CVE-2022-43847 affects IBM Aspera Console versions 3.4.0 through 3.4.4.
5
Can CVE-2022-43847 be exploited remotely?
Yes, CVE-2022-43847 can be exploited remotely by attackers to gain access to sensitive cookie information.