IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
History

Thu, 31 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 00:00:00 +0000

Type Values Removed Values Added
Description IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
Title IBM Aspera Faspex bypass security
First Time appeared Ibm
Ibm aspera Faspex
Weaknesses CWE-602
CPEs cpe:2.3:a:ibm:aspera_faspex:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.12.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex:5.0.8:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Faspex
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-07-30T23:47:25.483Z

Updated: 2025-07-31T17:55:40.360Z

Reserved: 2025-04-15T21:16:09.685Z

Link: CVE-2025-36039

cve-icon Vulnrichment

Updated: 2025-07-31T13:39:40.953Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-31T00:15:26.347

Modified: 2025-07-31T18:42:37.870

Link: CVE-2025-36039

cve-icon Redhat

No data.