First published: Wed Feb 05 2025(Updated: )
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Shares | <=1.9.0 - 1.10.0 PL6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-56470 is classified as a medium vulnerability due to its potential to facilitate unauthorized access and network enumeration.
To fix CVE-2024-56470, upgrade IBM Aspera Shares to a version beyond 1.10.0 PL6, where the vulnerability has been addressed.
CVE-2024-56470 can facilitate server-side request forgery (SSRF) attacks, allowing unauthorized requests from the server.
CVE-2024-56470 requires authenticated access, making it primarily exploitable by users with credentials.
The risks associated with CVE-2024-56470 include potential unauthorized actions and data exposure due to network enumeration.