No analysis available yet.
Vendor Solution
IBM strongly recommends addressing the vulnerabilities now by upgrading to 2.3.2, see links in the table below. ProductFixing VRMPlatformLink to FixIBM Aspera HTTP Gateway2.3.2Linux click here https://www.ibm.com/support/fixcentral/swg/downloadFixes
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31353 | IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7246284 |
|
Thu, 11 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:aspera_http_gateway:*:*:*:*:*:linux:*:* |
Fri, 26 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user. | |
| Title | IBM Aspera HTTP Gateway information disclosure | |
| First Time appeared |
Ibm
Ibm aspera Http Gateway |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:ibm:aspera_http_gateway:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_http_gateway:2.3.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Http Gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-26T14:57:32.217Z
Reserved: 2025-04-15T21:16:46.801Z
Link: CVE-2025-36274
Updated: 2025-09-26T14:57:22.186Z
Status : Analyzed
Published: 2025-09-26T15:16:03.207
Modified: 2025-12-11T22:12:13.223
Link: CVE-2025-36274
No data.
OpenCVE Enrichment
No data.
EUVD