Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37263 | IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:* |
Mon, 16 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Sep 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system. | |
| Title | IBM Aspera Shares session fixation | |
| First Time appeared |
Ibm
Ibm aspera Shares |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:aspera_shares:1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Shares |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-16T15:16:30.485Z
Reserved: 2024-06-13T21:43:46.666Z
Link: CVE-2024-38315
Updated: 2024-09-16T15:16:25.620Z
Status : Analyzed
Published: 2024-09-16T15:15:16.087
Modified: 2024-09-20T14:09:24.733
Link: CVE-2024-38315
No data.
OpenCVE Enrichment
No data.
EUVD