CVE-2023-37413: IBM Aspera Faspex information disclosure
Published Jan 28, 2025
·Updated
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
Other sources
IBM Aspera Faspex could disclose sensitive username information due to an observable response discrepancy.
— IBM
Affected Software
2 affected components
IBM Aspera Faspex 5<=5.0.0 - 5.0.10
IBM Aspera Faspex>=5.0.0<=5.0.10
Event History
Jan 28, 2025
CVE Published
via IBM·12:00 AM
Jan 29, 2025
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37413?
CVE-2023-37413 has been classified with a high severity due to its potential to disclose sensitive username information.
2
How do I fix CVE-2023-37413?
To fix CVE-2023-37413, update IBM Aspera Faspex to a version beyond 5.0.10.
3
What types of systems are affected by CVE-2023-37413?
CVE-2023-37413 affects IBM Aspera Faspex versions 5.0.0 through 5.0.10.
4
What information can be disclosed due to CVE-2023-37413?
CVE-2023-37413 can disclose sensitive username information through an observable response discrepancy.
5
Is CVE-2023-37413 easy to exploit?
CVE-2023-37413 could be relatively easy to exploit, as it relies on observable response discrepancies.