CVE-2022-43852: IBM Aspera Console information disclosure
Published Apr 14, 2025
·Updated
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.
Affected Software
4 affected components
IBM Aspera Console>=3.4.0<=3.4.4
All of the following
IBM Aspera Console>=3.4.0<3.4.5
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Apr 14, 2025
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43852?
CVE-2022-43852 has been rated as a medium severity vulnerability due to its potential for disclosing sensitive information.
2
How does CVE-2022-43852 affect IBM Aspera Console?
CVE-2022-43852 affects IBM Aspera Console versions 3.4.0 to 3.4.4 by potentially exposing sensitive information in HTTP headers.
3
What types of attacks can result from CVE-2022-43852?
CVE-2022-43852 can lead to further attacks that exploit the disclosed sensitive information to compromise the system.
4
How do I fix CVE-2022-43852?
To mitigate CVE-2022-43852, it is recommended to update IBM Aspera Console to a version later than 3.4.4.
5
Is CVE-2022-43852 publicly known?
Yes, CVE-2022-43852 is publicly acknowledged and documented in vulnerability databases.