Unauthorized Action Vulnerability in IBM Aspera Faspex Product
CVE-2025-36040

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
31 July 2025

What is CVE-2025-36040?

IBM Aspera Faspex versions 5.0.0 through 5.0.12.1 are susceptible to a vulnerability that permits authenticated users to execute unauthorized actions. This issue arises from the reliance on client-side enforcement of server-side security mechanisms, which can be exploited by users to bypass intended security protocols, leading to potential misuse of the service. Addressing this oversight is critical for maintaining the integrity and security of the application.

Affected Version(s)

Aspera Faspex 5.0.0 <= 5.0.12.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-36040 : Unauthorized Action Vulnerability in IBM Aspera Faspex Product