IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
The server contains a protection mechanism that assumes that any URI that is accessed using HTTP GET will not cause a state change to the associated resource. This might allow attackers to bypass intended access restrictions and conduct resource modification and deletion attacks, since some applications allow GET to modify state.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Aspera_faspex | Ibm | 5.0.0 (including) | 5.0.10 (excluding) |