Permission Misconfiguration in IBM Aspera Faspex Affects User Access
CVE-2025-36228
3.8LOW
What is CVE-2025-36228?
IBM Aspera Faspex versions 5.0.0 through 5.0.14.1 exhibit a vulnerability related to inconsistent permissions between the user interface and backend API. This discrepancy may allow users to inadvertently access features that should be disabled, leading to potential misuse of the system. Organizations are advised to review their configurations and apply security patches to mitigate the risks associated with this issue.
Affected Version(s)
Aspera Faspex 5 5.0.0 <= 5.0.14.1
References
CVSS V3.1
Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved