CVE-2025-36226
published 2026-03-10CVE-2025-36226: IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.21%
11.2th percentile
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aspera_faspex | >= 5.0.0 < 5.0.15 | 5.0.15 |
| ibm | aspera_faspex_5 | 5.0.0 – 5.0.14.3 | — |
| msrc | cm1_openldap_2.4.57-2_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3p7w-95xq-82gp: IBM Aspera Faspex 5 5
ghsa_unreviewed·2026-03-10
CVE-2025-36226 [MEDIUM] CWE-79 GHSA-3p7w-95xq-82gp: IBM Aspera Faspex 5 5
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Microsoft
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing resulting in denial of service.
vendor_msrc·2021-01-12·CVSS 7.5
CVE-2020-36226 [HIGH] A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing resulting in denial of service.
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing resulting in denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: M
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-36227 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-36227 [MEDIUM] CVE-2025-36227 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36227 :
IBM Aspera Faspex vulnerability analysis and mitigation
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Source : NVD
## 5.4
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
IBM Aspera Faspex
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:aspera_faspex
Sources
Linux Severity MEDIUM Has Fix Added
Wiz
CVE-2025-36230 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-36230 [MEDIUM] CVE-2025-36230 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36230 :
IBM Aspera Faspex vulnerability analysis and mitigation
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Source : NVD
## 5.4
Score
Published December 26, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
IBM Aspera Faspex
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:aspera_faspex
Sources
Linux Severity MEDIUM Has Fix Added at: Dec 30, 2025
Linux Severity MEDIUM Has Fix Added
Wiz
CVE-2025-36226 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-36226 [MEDIUM] CVE-2025-36226 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36226 :
IBM Aspera Faspex vulnerability analysis and mitigation
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Source : NVD
## 5.4
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
IBM Aspera Faspex
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:aspera_faspex
Sources
Linux Severity MEDIUM Has Fix Added at: Mar
Wiz
CVE-2025-36229 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-36229 [MEDIUM] CVE-2025-36229 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36229 :
IBM Aspera Faspex vulnerability analysis and mitigation
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
Source : NVD
## 4.3
Score
Published December 26, 2025
Severity MEDIUM
CNA Score 3.1
Affected Technologies
IBM Aspera Faspex
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:aspera_faspex
Sources
Linux Severity MEDIUM Has Fix Added at: Dec 30, 2025
Linux Severity MEDIUM Has Fix Added at: Dec 31, 2025
## Get a CVE risk assessment
Get a prioritized view of CVEs in y
Wiz
CVE-2025-36228 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-36228 [MEDIUM] CVE-2025-36228 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36228 :
IBM Aspera Faspex vulnerability analysis and mitigation
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
Source : NVD
## 3.8
Score
Published December 26, 2025
Severity LOW
CNA Score 3.8
Affected Technologies
IBM Aspera Faspex
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:aspera_faspex
Sources
Linux Severity LOW Has Fix Added at: Dec 30, 2025
Linux Severity LOW Has Fix Added at: Dec 31, 2025
## Get a CVE risk assess
2026-03-10
Published