Executive brief
IBM Aspera High-Speed Transfer Server and Endpoint, which are used for rapid large-scale data transfers, contain a security vulnerability in their web handling component. An authenticated user could exploit this flaw to run unauthorized commands or malicious code on the underlying system. This could lead to a full system compromise, data theft, or disruption of file transfer operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in the asperahttpd component of IBM Aspera High-Speed Transfer Server and Endpoint. The vulnerability is reachable over the network and requires low-privileged authentication (PR:L). By sending specially crafted input to the affected component, an attacker can overflow the stack buffer to hijack the execution flow. Successful exploitation allows for arbitrary code execution with the privileges of the asperahttpd process. The issue is resolved in version 4.4.7 Fix Pack 2.
Affected products
- IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1
- IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1
Timeline
- 2026-05-21: advisory: Initial publication by IBM
- 2026-05-22: other: Updated product versions in documentation
- 2026-05-27: disclosed: NVD publication date