top of page
perceptive_background_267k.jpg

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 22:02:06

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Data Breach & Exfiltration

CVE-2026-14973 affects IBM Aspera Desktop App versions 1.0.5 through 1.0.19. The vulnerability allows files to be written outside of the user's selected download destination, indicating a path traversal or directory escape issue. This could allow an attacker or malicious content to place files in arbitrary locations on the user's filesystem. The scope of affected versions spans a wide range of the product lifecycle. IBM has published a support advisory addressing this issue. The vulnerability is classified with a high criticality rating. No additional technical details or exploit code are referenced in the advisory.

Technical details

Mitigation steps:

Affected products:

IBM Aspera Desktop App 1.0.5 through 1.0.19

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page