Project Subscriptions
No advisories yet.
Solution
Product(s)VRMFRemediation/First FixIBM Aspera High-Speed Transfer Server for Cloud Pak for Integration (CP4I)1.5.20- Access your charts to get the latest version
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7274127 |
|
Thu, 11 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place. |
Fri, 29 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm aspera High-speed Transfer Server For Cloud Pak For Integration
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:ibm:aspera_high-speed_transfer_server_for_cloud_pak_for_integration:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm aspera High-speed Transfer Server For Cloud Pak For Integration
|
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 | |
| Title | Authentication bypass vulnerability found in Aspera High-Speed Transfer Server for Cloud Pak for Integration | |
| First Time appeared |
Ibm
Ibm aspera Hsts For Cp4i |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:ibm:aspera_hsts_for_cp4i:1.5.19:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_hsts_for_cp4i:1.5.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Hsts For Cp4i |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-06-11T14:05:33.251Z
Reserved: 2026-05-05T16:12:39.223Z
Link: CVE-2026-7876
Updated: 2026-05-28T14:21:55.302Z
Status : Modified
Published: 2026-05-27T14:17:35.727
Modified: 2026-06-11T14:16:32.763
Link: CVE-2026-7876
No data.
OpenCVE Enrichment
Updated: 2026-05-29T23:00:14Z