← Vulnerability feed

Vulnerability record · CVE-2022-43847 · published 14 April 2025

CVE-2022-43847: Ibm aspera console vulnerability

Ibm · Aspera Console

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

5.4 CVSS 3.1 Medium EPSS 0.23% · top 87.4% CWE-644 · CWE-644
5.4CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-43847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2022-43842Ibm aspera console sql injection vulnerabilityIBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…EPSS 0.53%8.8CVE-2023-27272Ibm aspera console weak password requirements vulnerabilityIBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.EPSS 0.25%8.6CVE-2025-13379Ibm aspera console sql injection vulnerabilityIBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…EPSS 0.37%8.0CVE-2021-38963Ibm aspera console csv injection vulnerabilityIBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection…EPSS 0.64%7.5CVE-2022-43851Ibm aspera console broken cryptographic algorithm vulnerabilityIBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive in…EPSS 0.22%7.5CVE-2022-43845Ibm aspera console incorrect permission assignment vulnerabilityIBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.…EPSS 0.43%6.1CVE-2021-38927Ibm aspera console cross-site scripting vulnerabilityIBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…EPSS 0.34%5.4CVE-2022-43850Ibm aspera console cross-site scripting vulnerabilityIBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in t…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2022-43847), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.