CVE-2025-3423: IBM Aspera Faspex 5 cross-site scripting
IBM Aspera Faspex 5 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3423?
CVE-2025-3423 is classified as a medium severity vulnerability due to its potential for credential disclosure.
How do I fix CVE-2025-3423?
To fix CVE-2025-3423, upgrade IBM Aspera Faspex to version 5.0.12 or later.
Who is affected by CVE-2025-3423?
CVE-2025-3423 affects users of IBM Aspera Faspex versions 5.0.0 to 5.0.11.
What type of vulnerability is CVE-2025-3423?
CVE-2025-3423 is a cross-site scripting (XSS) vulnerability.
Can CVE-2025-3423 lead to more serious attacks?
Yes, CVE-2025-3423 can lead to credential disclosure within a trusted session, increasing the risk of further attacks.