CVE-2023-35907: IBM Aspera Faspex information disclosure
IBM Aspera does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35907?
CVE-2023-35907 has been classified with a medium severity level due to its potential to allow unauthorized access through weak passwords.
How do I fix CVE-2023-35907?
To fix CVE-2023-35907, implement strong password policies and ensure that users create complex passwords.
Which versions of IBM Aspera are affected by CVE-2023-35907?
CVE-2023-35907 affects IBM Aspera Faspex versions 5.0.0 to 5.0.10.
What are the risks associated with CVE-2023-35907?
The risks associated with CVE-2023-35907 include increased vulnerability to unauthorized account access due to weak passwords.
Is there an official patch for CVE-2023-35907?
Yes, IBM may provide guidance on security patches or updates to address CVE-2023-35907; consult their support resources for details.