Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
IBM strongly recommends addressing the vulnerabilities now by upgrading to Faspex 5.0.14 available from the link below.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7255331 |
|
Mon, 29 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm aspera Faspex
|
|
| CPEs | cpe:2.3:a:ibm:aspera_faspex:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm aspera Faspex
|
Fri, 26 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse. | |
| Title | Incorrect Execution-Assigned Permissions in IBM Aspera Faspex | |
| First Time appeared |
Ibm
Ibm aspera Faspex 5 |
|
| Weaknesses | CWE-279 | |
| CPEs | cpe:2.3:a:ibm:aspera_faspex_5:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex_5:5.0.14.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Faspex 5 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-12-26T15:15:06.304Z
Reserved: 2025-04-15T21:16:41.802Z
Link: CVE-2025-36228
Updated: 2025-12-26T15:14:05.661Z
Status : Analyzed
Published: 2025-12-26T15:15:46.540
Modified: 2025-12-29T18:15:10.767
Link: CVE-2025-36228
No data.
OpenCVE Enrichment
No data.