Skip to main content

Vendor/product archive

ibm / aspera_console CVEs

Beta · best-effort

18 CVEs tagged to ibm / aspera_console0 Critical, 4 High, 11 Medium, 3 Low, 0 Unrated.

CVE-2025-13379

Published Feb 5, 2026

IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add,…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13925

Published Jan 20, 2026

IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-43840

Published Apr 14, 2025

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43841

Published May 30, 2024

IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43575

Published May 30, 2024

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43384

Published May 30, 2024

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1