CVE-2025-36230: XSS in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM Aspera Faspex 5 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36230?
CVE-2025-36230 is classified as a high severity vulnerability due to its potential for remote code execution via HTML injection.
How do I fix CVE-2025-36230?
To fix CVE-2025-36230, users should update IBM Aspera Faspex to version 5.0.15 or later.
What are the potential impacts of CVE-2025-36230?
The potential impacts of CVE-2025-36230 include the unauthorized execution of malicious code in users' web browsers.
Who is affected by CVE-2025-36230?
CVE-2025-36230 affects IBM Aspera Faspex versions 5.0.0 through 5.0.14.1.
Can CVE-2025-36230 be exploited remotely?
Yes, CVE-2025-36230 can be exploited remotely, allowing attackers to inject malicious HTML code.