CVE-2024-45096: IBM Aspera Faspex information disclosure
Published Sep 4, 2024
·Updated
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.
Other sources
IBM Aspera Faspex could allow a user with access to the package to obtain sensitive information through a directory listing.
— IBM
Affected Software
2 affected components
IBM Aspera Faspex 5<=5.0.0 - 5.0.9
IBM Aspera Faspex>=5.0.0<5.0.10
Event History
Sep 4, 2024
CVE Published
via IBM·12:00 AM
Sep 5, 2024
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What versions of IBM Aspera Faspex are affected by CVE-2024-45096?
IBM Aspera Faspex versions 5.0.0 through 5.0.9 are affected by CVE-2024-45096.
2
What kind of information can be exposed due to CVE-2024-45096?
CVE-2024-45096 can allow a user to obtain sensitive information through a directory listing.
3
What is the severity level of CVE-2024-45096?
The severity level of CVE-2024-45096 is classified as medium.
4
How can I mitigate the risk associated with CVE-2024-45096?
To mitigate CVE-2024-45096, it is recommended to upgrade to IBM Aspera Faspex version 5.0.10 or later.
5
Is there a known fix for CVE-2024-45096?
Yes, upgrading to IBM Aspera Faspex version 5.0.10 or later resolves the vulnerability described in CVE-2024-45096.