CVE-2025-36228: Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
Other sources
IBM Aspera Faspex 5 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36228?
CVE-2025-36228 has been classified as a moderate severity vulnerability due to the risk of unauthorized access caused by inconsistent permissions.
How do I fix CVE-2025-36228?
To fix CVE-2025-36228, ensure that your IBM Aspera Faspex is updated to version 5.0.14.2 or later, where the permissions issue is addressed.
What are the consequences of exploiting CVE-2025-36228?
Exploiting CVE-2025-36228 may allow users to access functions that should be disabled, leading to potential misuse of the system.
Which versions of IBM Aspera Faspex are affected by CVE-2025-36228?
IBM Aspera Faspex versions from 5.0.0 to 5.0.14.1 are affected by CVE-2025-36228.
Is authentication impacted by CVE-2025-36228?
CVE-2025-36228 may affect authentication by allowing unauthorized users to access features due to inconsistent permissions.