Information Disclosure Vulnerability in IBM Aspera Faspex by IBM
CVE-2025-36229

3.1LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
26 December 2025

What is CVE-2025-36229?

IBM Aspera Faspex is prone to an information disclosure vulnerability that enables authenticated users to enumerate sensitive data by exploiting package identifiers. This weakness could lead to unauthorized access to confidential information, posing significant risks to data integrity and confidentiality.

Affected Version(s)

Aspera Faspex 5 5.0.0 <= 5.0.14.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36229 : Information Disclosure Vulnerability in IBM Aspera Faspex by IBM