Executive brief
IBM Aspera Enterprise WebApps is a web-based file transfer and collaboration platform. A local attacker with access to the container environment could bypass container security boundaries by exploiting unrestricted system calls, potentially gaining unauthorized access to the host system or other containers and compromising data isolation and operational integrity.
Technical details
The vulnerability is a container escape flaw in IBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5. The underlying cause is inadequate syscall filtering or seccomp policies within the container, allowing a local attacker with container access to execute privileged or unrestricted system calls. The attack requires local/container-level access (not network-based). A successful exploit enables an attacker to escape container protections, gain access to the host system, or interact with other containers. The issue is fixed in version 1.0.6 or later.
Affected products
- IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixed in version 1.0.6