CVE-2024-56470

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVSS

No CVSS.

References
Link Resource
https://www.ibm.com/support/pages/node/7182490 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level4:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level5:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level6:*:*:*:*:*:*

History

07 Mar 2025, 19:37

Type Values Removed Values Added
First Time Ibm
Ibm aspera Shares
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : unknown
References () https://www.ibm.com/support/pages/node/7182490 - () https://www.ibm.com/support/pages/node/7182490 - Vendor Advisory
CPE cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level4:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level6:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level5:*:*:*:*:*:*
CWE CWE-918

05 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 23:15

Updated : 2025-03-07 19:37


NVD link : CVE-2024-56470

Mitre link : CVE-2024-56470


JSON object : View

Products Affected

ibm

  • aspera_shares
CWE

No CWE.