CVE-2024-56471: IBM Aspera Shares Server-Side Request Forgery
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Other sources
IBM Aspera Shares is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56471?
CVE-2024-56471 is classified as a moderate severity vulnerability due to its potential for unauthorized network access.
Who is affected by CVE-2024-56471?
IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 are affected by CVE-2024-56471.
How do I fix CVE-2024-56471?
To remediate CVE-2024-56471, upgrade IBM Aspera Shares to version 1.10.0 PL7 or later.
What type of vulnerability is CVE-2024-56471?
CVE-2024-56471 is a server-side request forgery (SSRF) vulnerability.
What could an attacker achieve with CVE-2024-56471?
An attacker could exploit CVE-2024-56471 to send unauthorized requests from the system, potentially leading to network enumeration.