CVE-2026-75777: Multiple vulnerabilities in IBM Aspera Enterprise Webapps
IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.
Other sources
IBM Aspera Enterprise WebApps could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera Enterprise WebAppsto a version that resolves this vulnerability.Fixed in 1.0.6
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 are identified as affected.
What level of access does an attacker need?
Exploitation requires local access with low privileges. No user interaction is required.
What is the potential impact after exploitation?
A local attacker could escape the container protections. The reported impact includes high confidentiality, integrity, and availability impact, with a changed scope.