CVE-2023-22862
05.06.2023, 00:15
IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | aspera_cargo | 𝑥 < 4.2.6 |
ibm | aspera_connect | 𝑥 < 4.2.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-523 - Unprotected Transport of CredentialsLogin pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.