Description
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
Published: 2026-07-28
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 contain a flaw in session‑management handling, as identified by CWE‑613. The vulnerability could allow an attacker to interfere with or misuse session data, potentially granting unauthorized access to services or sensitive resources. The official CVE description does not detail specific privilege escalation or data‑exfiltration capability, but the high CVSS score of 8.2 indicates a serious risk if the flaw can be exploited.

Affected Systems

The vulnerable range applies to installations of IBM Aspera Faspex 5 on Linux platforms, specifically versions 5.0.0 up to and including 5.0.15.4, as the advisory only references a recommended upgrade path for Linux.

Risk and Exploitability

The severity rating of 8.2 reflects significant potential impact, while the EPSS score of less than 1% indicates that the vulnerability is currently rarely exploited in the wild. It is not listed in the CISA KEV catalog, suggesting no confirmed operational exploitation. The description does not state the exact exploitation method, but the session‑management nature and common web‑based exposure of such flaws imply a likely remote attack vector via session tokens or cookies, a scenario inferred from typical use of the product.

Generated by OpenCVE AI on August 4, 2026 at 12:49 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading: ProductVersionPlatformLink to FixIBM Aspera Faspex5.0.16Linux Link https://www.ibm.com/support/fixcentral/swg/downloadFixes


OpenCVE Recommended Actions

  • Upgrade IBM Aspera Faspex to version 5.0.16 or later, following IBM’s published fix path.
  • After upgrading, ensure that session‑management controls—such as secure cookie flags, appropriate session timeouts, and server‑side invalidation—are correctly configured as recommended by IBM.
  • Continuously monitor authentication and session logs for unusual activity that could indicate exploitation attempts post-patch.

Generated by OpenCVE AI on August 4, 2026 at 12:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
Title Multiple vulnerabilities in IBM Aspera Faspex
First Time appeared Ibm
Ibm aspera Faspex 5
Weaknesses CWE-613
CPEs cpe:2.3:a:ibm:aspera_faspex_5:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex_5:5.0.15.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Faspex 5
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Ibm Aspera Faspex Aspera Faspex 5
Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T14:10:07.644Z

Reserved: 2026-07-07T18:59:33.610Z

Link: CVE-2026-14996

cve-icon Vulnrichment

Updated: 2026-07-29T14:09:16.223Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:27.240

Modified: 2026-08-05T19:32:44.053

Link: CVE-2026-14996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:00:11Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration