Home/Product/ibm aspera console
Product

ibm aspera console

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-13460
>= 3.3.0 and < 3.4.9
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.
5.3MEDIUM
CVE-2025-13459
>= 3.3.0 and < 3.4.9
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of b
2.7LOW
CVE-2025-13212
>= 3.3.0 and < 3.4.9
IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to
5.3MEDIUM
CVE-2025-13379
>= 3.4.0 and <= 3.4.8
IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen
8.6HIGH
CVE-2025-13925
all versions
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.
4.9MEDIUM
CVE-2023-27272
>= 3.4.0 and < 3.4.5
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
3.1LOW
CVE-2022-43852
>= 3.4.0 and < 3.4.5
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks
5.3MEDIUM
CVE-2022-43851
>= 3.4.0 and < 3.4.5
IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt
5.9MEDIUM
CVE-2022-43850
>= 3.4.0 and < 3.4.5
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary
5.4MEDIUM
CVE-2022-43847
>= 3.4.0 and < 3.4.5
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOS
5.4MEDIUM
CVE-2022-43840
>= 3.4.0 and <= 3.4.4
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated atta
4.3MEDIUM
CVE-2022-43845
>= 3.4.0 and < 3.4.5
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set
3.7LOW
CVE-2021-38963
>= 3.4.0 and < 3.4.5
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused
8.0HIGH
CVE-2022-43841
>= 3.4.0 and <= 3.4.2
IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system.
4.0MEDIUM
CVE-2022-43575
>= 3.4.0 and <= 3.4.2
IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
5.4MEDIUM
CVE-2022-43384
>= 3.4.0 and <= 3.4.2
IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
4.6MEDIUM
CVE-2022-43842
>= 3.4.0 and < 3.4.2
IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statemen
8.6HIGH
CVE-2021-38927
< 3.4.2
IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code
7.2HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin