Back

MEDIUM

IBM Aspera Console cross-site scripting

Published May 30, 2024

Description

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 238645.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published May 30, 2024
Updated Aug 3, 2024
Reserved Oct 17, 2022

CISA Vulnrichment

Updated May 30, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published May 30, 2024
Updated Aug 3, 2024

GitHub

No data