Unauthorized Action Vulnerability in IBM Aspera Faspex Product
CVE-2025-36040
6.5MEDIUM
What is CVE-2025-36040?
IBM Aspera Faspex versions 5.0.0 through 5.0.12.1 are susceptible to a vulnerability that permits authenticated users to execute unauthorized actions. This issue arises from the reliance on client-side enforcement of server-side security mechanisms, which can be exploited by users to bypass intended security protocols, leading to potential misuse of the service. Addressing this oversight is critical for maintaining the integrity and security of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Aspera Faspex 5.0.0 <= 5.0.12.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published