Executive brief
IBM Aspera High-Speed Transfer Server is a high-performance file transfer solution used to move large data sets across global networks. A security flaw in this product allows unauthorized users to bypass authentication and access files stored on the server. This could lead to the theft or modification of sensitive corporate data and significant operational disruption.
Technical details
An authentication bypass vulnerability (CWE-287) exists in IBM Aspera High-Speed Transfer Server (HSTS) for Cloud Pak for Integration (CP4I). The flaw allows a transfer client to bypass security checks and access files in the server's local storage that should otherwise be restricted. The vulnerability is exploitable over the network without authentication (PR:N) or user interaction (UI:N) when specific restriction settings are not in place. Successful exploitation grants the attacker high-impact access to read and modify files (C:H/I:H). The issue is resolved in version 1.5.20.
Affected products
- IBM Aspera High-Speed Transfer Server for Cloud Pak for Integration (CP4I) 1.5.1 - 1.5.19
Timeline
- 2026-05-26: advisory: Initial publication by IBM
- 2026-05-26: patched: Version 1.5.20 released
- 2026-05-27: disclosed: NVD publication date