IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Aspera_cargo | Ibm | * | 4.2.6 (excluding) |
Aspera_connect | Ibm | * | 4.2.6 (excluding) |