CVE-2023-37411: IBM Aspera Faspex cross-site scripting
IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260139.
Other sources
IBM Aspera Faspex is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37411?
CVE-2023-37411 is considered to have a high severity level due to its potential for cross-site scripting exploits.
How do I fix CVE-2023-37411?
To fix CVE-2023-37411, upgrade IBM Aspera Faspex to version 5.0.7 or later.
What is the impact of CVE-2023-37411?
The impact of CVE-2023-37411 includes the potential exposure of users' credentials through arbitrary JavaScript code execution.
Who is affected by CVE-2023-37411?
CVE-2023-37411 affects users of IBM Aspera Faspex versions 5.0.0 to 5.0.6.
Is there a workaround for CVE-2023-37411?
There are no official workarounds for CVE-2023-37411; upgrading to a fixed version is recommended.