IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
Advisories
No advisories yet.
Fixes
Solution
IBM strongly recommends addressing the vulnerability now by upgrading: ProductVersion(s)LinkIBM Aspera Desktop App1.1.0Users can upgrade to the new version directly through the application or from IBM Aspera Downloads https://ibmaspera.com/help/downloads/desktop
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7280939 |
|
History
Tue, 28 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. | |
| Title | Path Traversal in IBM Desktop App | |
| First Time appeared |
Ibm
Ibm aspera Desktop App |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ibm:aspera_desktop_app:1.0.19:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_desktop_app:1.0.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Desktop App |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-07-28T20:31:29.940Z
Reserved: 2026-07-07T16:44:30.497Z
Link: CVE-2026-14973
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses