CVE-2024-56473: IBM Aspera Shares Data Manipulation
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
Other sources
IBM Aspera Shares could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56473?
CVE-2024-56473 is classified as a medium severity vulnerability due to the potential for IP address spoofing.
How do I fix CVE-2024-56473?
To fix CVE-2024-56473, upgrade IBM Aspera Shares to a version later than 1.10.0 PL6.
What versions of IBM Aspera Shares are affected by CVE-2024-56473?
IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 are affected by CVE-2024-56473.
What type of attack does CVE-2024-56473 enable?
CVE-2024-56473 enables attackers to spoof their IP addresses, impacting log file integrity.
Is CVE-2024-56473 related to header manipulation?
Yes, CVE-2024-56473 is related to improper verification of 'Client-IP' headers, allowing IP spoofing.