IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7182490 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Mar 2025, 19:37
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ibm
Ibm aspera Shares |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
References | () https://www.ibm.com/support/pages/node/7182490 - Vendor Advisory | |
CPE | cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level4:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level6:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level5:*:*:*:*:*:* |
|
CWE |
05 Feb 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-05 23:15
Updated : 2025-03-07 19:37
NVD link : CVE-2024-56470
Mitre link : CVE-2024-56470
JSON object : View
Products Affected
ibm
- aspera_shares
CWE
No CWE.