Impact
IBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 allow a local attacker to escape container protections because unrestricted system calls are permitted within the container. This weakness is classified as CWE‑269 and could enable elevation of privileges on the host.
Affected Systems
IBM Aspera Enterprise WebApps products, specifically versions 1.0.0 to 1.0.5, are vulnerable. The vulnerability exists across Linux-based installations that deploy the containerized webapps.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity threat, and the EPSS score is not available. This vulnerability is not listed in the CISA KEV catalog. A local attacker can trigger unrestricted system calls to escape container isolation, potentially gaining elevated privileges on the host.
OpenCVE Enrichment