CVE-2025-36229: Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
Other sources
IBM Aspera Faspex could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36229?
CVE-2025-36229 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2025-36229?
To fix CVE-2025-36229, update IBM Aspera Faspex to version 5.0.15 or later.
What type of vulnerability is CVE-2025-36229?
CVE-2025-36229 is an information disclosure vulnerability affecting IBM Aspera Faspex.
Who is affected by CVE-2025-36229?
Individuals using IBM Aspera Faspex versions 5.0.0 through 5.0.14.1 are affected by CVE-2025-36229.
Can CVE-2025-36229 be exploited by unauthenticated users?
No, CVE-2025-36229 requires authentication for exploitation, as it affects authenticated users.