CVE-2023-22870: IBM Aspera Faspex information disclosure
Published Aug 29, 2023
·Updated
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 244121.
Affected Software
3 affected components
IBM Aspera Faspex<=5.0.5 and prior
IBM Aspera Faspex<=5.0.5
Linux Linux Kernel
Remediation
Patch Available
Event History
Aug 29, 2023
CVE Published
via IBM·12:00 AM
Sep 5, 2023
CVE Published
via MITRE·12:46 AM
Data Sourced
via MITRE·12:46 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for IBM Aspera Faspex?
The vulnerability ID for IBM Aspera Faspex is CVE-2023-22870.
2
What is the severity of CVE-2023-22870?
The severity of CVE-2023-22870 is medium.
3
How does CVE-2023-22870 affect IBM Aspera Faspex?
CVE-2023-22870 allows an attacker to obtain sensitive information in cleartext using man-in-the-middle techniques.
4
Which versions of IBM Aspera Faspex are affected by CVE-2023-22870?
IBM Aspera Faspex version 5.0.5 and prior are affected by CVE-2023-22870.
5
Is Linux Kernel affected by CVE-2023-22870?
No, Linux Kernel is not affected by CVE-2023-22870.