IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Aspera_cargo | Ibm | * | 4.2.6 (excluding) |
| Aspera_connect | Ibm | * | 4.2.6 (excluding) |