Cross-Site Scripting in IBM Aspera Shares Affects User Security
CVE-2024-38317

4.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
5 February 2025

Summary

IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 are susceptible to a cross-site scripting (XSS) vulnerability. This issue allows a privileged user to inject arbitrary JavaScript code into the Web UI. Such exploitation can modify the intended functionality of the application, potentially leading to the exposure of sensitive user credentials within a trusted session.

Affected Version(s)

Aspera Shares 1.9.0 <= 1.10.0 PL6

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.