CVE-2024-45097: IBM Aspera Faspex bypass security
Published Sep 4, 2024
·Updated
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
Other sources
IBM Aspera Faspex could allow a user to bypass intended access restrictions and conduct resource modification.
— IBM
Affected Software
2 affected components
IBM Aspera Faspex 5<=5.0.0 - 5.0.9
IBM Aspera Faspex>=5.0.0<5.0.10
Event History
Sep 4, 2024
CVE Published
via IBM·12:00 AM
Sep 5, 2024
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45097?
CVE-2024-45097 is rated as a high severity vulnerability due to the potential for access restriction bypass and resource modification.
2
How do I fix CVE-2024-45097?
To mitigate CVE-2024-45097, upgrade IBM Aspera Faspex to version 5.0.10 or later.
3
What are the risks associated with CVE-2024-45097?
The risks include unauthorized access to resources and potential modification of sensitive data.
4
Which versions of IBM Aspera Faspex are affected by CVE-2024-45097?
IBM Aspera Faspex versions 5.0.0 through 5.0.9 are affected by CVE-2024-45097.
5
Who is responsible for addressing CVE-2024-45097?
IBM is responsible for providing patches and updates to address CVE-2024-45097.