Information Disclosure Vulnerability in IBM Aspera Faspex by IBM
CVE-2025-36229
3.1LOW
What is CVE-2025-36229?
IBM Aspera Faspex is prone to an information disclosure vulnerability that enables authenticated users to enumerate sensitive data by exploiting package identifiers. This weakness could lead to unauthorized access to confidential information, posing significant risks to data integrity and confidentiality.
Affected Version(s)
Aspera Faspex 5 5.0.0 <= 5.0.14.1
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved