First published: Thu Apr 18 2024(Updated: )
IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Faspex 5 | <=5.0.0 - 5.0.7 | |
IBM Aspera Faspex | >=5.0.0<5.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22869 has not been explicitly assigned a CVSS score, but it involves exposure of sensitive information which could pose a security risk.
To fix CVE-2023-22869, it is recommended to upgrade IBM Aspera Faspex to version 5.0.8 or later.
CVE-2023-22869 affects IBM Aspera Faspex versions 5.0.0 through 5.0.7.
Local users with access to the log files of IBM Aspera Faspex may be impacted by CVE-2023-22869.
CVE-2023-22869 may lead to exposure of potentially sensitive information that is logged by IBM Aspera Faspex.