Metrics
Affected Vendors & Products
No advisories yet.
Solution
IBM strongly recommends addressing the vulnerabilities now by upgrading to Faspex 5.0.14 available from the link below. ProductFixing VRMPlatformLink to FixIBM Aspera Faspex5.0.14 Linux click here https://www.ibm.com/support/fixcentral/swg/downloadFixes
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7247502 |
|
Tue, 14 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:ibm:aspera_faspex:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows |
Thu, 09 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. | |
| Title | IBM Aspera Faspex cross-origin resource sharing | |
| First Time appeared |
Ibm
Ibm aspera Faspex |
|
| Weaknesses | CWE-942 | |
| CPEs | cpe:2.3:a:ibm:aspera_faspex:5.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.13.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Faspex |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-10-09T19:06:07.254Z
Reserved: 2023-07-05T15:59:03.335Z
Link: CVE-2023-37401
Updated: 2025-10-09T19:06:04.012Z
Status : Analyzed
Published: 2025-10-09T14:15:53.703
Modified: 2025-10-14T20:18:35.280
Link: CVE-2023-37401
No data.
OpenCVE Enrichment
No data.