IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6963662 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/249847 | vdb entry vendor advisory |