Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10850 | IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7230757 |
|
Fri, 18 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel |
|
| CPEs | cpe:2.3:a:ibm:aspera_faspex:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel |
Mon, 14 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Apr 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM Aspera Faspex 5 cross-site scripting | |
| First Time appeared |
Ibm
Ibm aspera Faspex |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:aspera_faspex:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.11:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Faspex |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-01T10:15:36.536Z
Reserved: 2025-04-07T14:58:49.159Z
Link: CVE-2025-3423
Updated: 2025-04-14T19:21:22.440Z
Status : Analyzed
Published: 2025-04-13T12:15:14.463
Modified: 2025-07-18T18:07:10.100
Link: CVE-2025-3423
No data.
OpenCVE Enrichment
No data.
EUVD