Unauthorized Action Vulnerability in IBM Aspera Faspex Product
CVE-2025-36040
6.5MEDIUM
What is CVE-2025-36040?
IBM Aspera Faspex versions 5.0.0 through 5.0.12.1 are susceptible to a vulnerability that permits authenticated users to execute unauthorized actions. This issue arises from the reliance on client-side enforcement of server-side security mechanisms, which can be exploited by users to bypass intended security protocols, leading to potential misuse of the service. Addressing this oversight is critical for maintaining the integrity and security of the application.
Affected Version(s)
Aspera Faspex 5.0.0 <= 5.0.12.1