Cross-Site Scripting Vulnerability in IBM Aspera Faspex Product
CVE-2025-36226
5.4MEDIUM
What is CVE-2025-36226?
The identified vulnerability in IBM Aspera Faspex 5.0.0 through 5.0.14.3 allows an authenticated user to exploit cross-site scripting. This security flaw permits the insertion of arbitrary JavaScript code within the web user interface, which can compromise the integrity of user sessions. As a result, sensitive information such as credentials may be exposed, raising serious security concerns for users relying on the application.
Affected Version(s)
Aspera Faspex 5 5.0.0 <= 5.0.14.3