📦 Aspera Console

by Ibm

🔍 What is Aspera Console?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-13379

HIGH CVSS 8.6 Feb 5, 2026

CVE-2025-13379 is a SQL injection vulnerability in IBM Aspera Console versions 3.4.0 through 3.4.8 that allows remote attackers to execute arbitrary SQL commands. This could enable attackers to read, ...

CVE-2021-38963

HIGH CVSS 8.0 Sep 25, 2024

This CSV injection vulnerability in IBM Aspera Console allows authenticated attackers to execute arbitrary code on affected systems by tricking users into opening malicious files. It affects IBM Asper...

CVE-2022-43842

HIGH CVSS 8.6 Feb 23, 2024

CVE-2022-43842 is a SQL injection vulnerability in IBM Aspera Console versions 3.4.0 through 3.4.2 that allows remote attackers to execute arbitrary SQL commands. This could enable attackers to view, ...

CVE-2021-38927

HIGH CVSS 7.2 Dec 25, 2023

IBM Aspera Console 3.4.0 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into the web interface. This could enable session hijacking, credentia...

CVE-2025-13925

MEDIUM CVSS 4.9 Jan 20, 2026

IBM Aspera Console 3.4.7 stores sensitive information in log files that could be accessed by local privileged users. This vulnerability allows attackers with local system access to potentially obtain ...

CVE-2022-43851

MEDIUM CVSS 5.9 Apr 14, 2025

IBM Aspera Console versions 3.4.0 through 3.4.4 use weak cryptographic algorithms that could allow attackers to decrypt sensitive data. This affects organizations using these specific versions of IBM'...

CVE-2022-43847

MEDIUM CVSS 5.4 Apr 14, 2025

IBM Aspera Console versions 3.4.0 through 3.4.4 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attackers to inject malicious HTTP headers, potentially ...

CVE-2022-43575

MEDIUM CVSS 5.4 May 30, 2024

IBM Aspera Console versions 3.4.0 through 3.4.2 PL5 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web interface. This could...