IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7273615 |
|
History
Wed, 27 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to. | |
| Title | Multiple vulnerabilities in Aspera applications. | |
| First Time appeared |
Ibm
Ibm aspera High Speed Transfer Endpoint Ibm aspera High Speed Transfer Server |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ibm:aspera_high_speed_transfer_endpoint:3.7.4:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_high_speed_transfer_endpoint:4.4.7:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_high_speed_transfer_server:3.7.4:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_high_speed_transfer_server:4.4.7:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera High Speed Transfer Endpoint Ibm aspera High Speed Transfer Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-05-27T13:21:43.995Z
Updated: 2026-05-27T14:47:20.101Z
Reserved: 2026-05-19T16:39:18.455Z
Link: CVE-2026-9035
Updated: 2026-05-27T14:47:13.357Z
Status : Awaiting Analysis
Published: 2026-05-27T14:17:38.913
Modified: 2026-05-27T14:53:51.833
Link: CVE-2026-9035
No data.