Ibm Aspera Faspex vulnerabilities

46 known vulnerabilities affecting ibm/aspera_faspex.

Total CVEs
46
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH12MEDIUM29LOW2

Vulnerabilities

Page 1 of 3
CVE-2025-36226MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.152026-03-10
CVE-2025-36226 [MEDIUM] CWE-79 CVE-2025-36226: IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-36227MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.152026-03-10
CVE-2025-36227 [MEDIUM] CWE-644 CVE-2025-36227: IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by imprope IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
nvd
CVE-2025-36229MEDIUMCVSS 4.3≥ 5.0.0, < 5.0.14.22025-12-26
CVE-2025-36229 [LOW] CWE-497 CVE-2025-36229: IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive in IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
nvd
CVE-2025-36230MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.14.22025-12-26
CVE-2025-36230 [MEDIUM] CWE-80 CVE-2025-36230: IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2025-36228LOWCVSS 3.8≥ 5.0.0, < 5.0.14.22025-12-26
CVE-2025-36228 [LOW] CWE-279 CVE-2025-36228: IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user inter IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
nvd
CVE-2023-37401MEDIUMCVSS 5.3≥ 5.0.0, < 5.0.14≥ 5.0.0, ≤ 5.0.13.12025-10-09
CVE-2023-37401 [MEDIUM] CWE-942 CVE-2023-37401: IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.
cvelistv5nvd
CVE-2025-36225MEDIUMCVSS 4.3≥ 5.0.0, < 5.0.14≥ 5.0.0, ≤ 5.0.13.12025-10-09
CVE-2025-36225 [MEDIUM] CWE-203 CVE-2025-36225: IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
cvelistv5nvd
CVE-2025-36171MEDIUMCVSS 4.9≥ 5.0.0, < 5.0.14≥ 5.0.0, ≤ 5.0.13.12025-10-09
CVE-2025-36171 [MEDIUM] CWE-770 CVE-2025-36171: IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
cvelistv5nvd
CVE-2025-36040MEDIUMCVSS 6.5≥ 5.0.0, ≤ 5.0.12.12025-07-31
CVE-2025-36040 [MEDIUM] CWE-613 CVE-2025-36040: IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized a IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
cvelistv5nvd
CVE-2025-36039MEDIUMCVSS 6.5≥ 5.0.0, ≤ 5.0.12.12025-07-31
CVE-2025-36039 [MEDIUM] CWE-602 CVE-2025-36039: IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized a IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
cvelistv5nvd
CVE-2025-33136HIGHCVSS 8.8≥ 5.0.0, < 5.0.12.1≥ 5.0.0, ≤ 5.0.122025-05-22
CVE-2025-33136 [HIGH] CWE-471 CVE-2025-33136: IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive informa IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
cvelistv5nvd
CVE-2025-33137HIGHCVSS 8.8≥ 5.0.0, < 5.0.12.1≥ 5.0.0, ≤ 5.0.122025-05-22
CVE-2025-33137 [HIGH] CWE-602 CVE-2025-33137: IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive informa IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.
cvelistv5nvd
CVE-2025-33138MEDIUMCVSS 6.1≥ 5.0.0, < 5.0.12.1≥ 5.0.0, ≤ 5.0.122025-05-22
CVE-2025-33138 [MEDIUM] CWE-80 CVE-2025-33138: IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inje IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
cvelistv5nvd
CVE-2025-3423MEDIUMCVSS 5.4≥ 5.0.0, < 5.0.12≥ 5.0.0, ≤ 5.0.112025-04-13
CVE-2025-3423 [MEDIUM] CWE-79 CVE-2025-3423: IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability all IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2023-35907CRITICALCVSS 9.8≥ 5.0.0, ≤ 5.0.102025-01-29
CVE-2023-35907 [MEDIUM] CWE-521 CVE-2023-35907: IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by d IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
cvelistv5nvd
CVE-2023-37398CRITICALCVSS 9.8≥ 5.0.0, ≤ 5.0.102025-01-29
CVE-2023-37398 [MEDIUM] CWE-521 CVE-2023-37398: IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by d IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
cvelistv5nvd
CVE-2023-37412MEDIUMCVSS 4.9≥ 5.0.0, ≤ 5.0.102025-01-29
CVE-2023-37412 [MEDIUM] CWE-250 CVE-2023-37412: IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
cvelistv5nvd
CVE-2023-37413MEDIUMCVSS 5.3≥ 5.0.0, ≤ 5.0.102025-01-29
CVE-2023-37413 [MEDIUM] CWE-204 CVE-2023-37413: IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an obser IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
cvelistv5nvd
CVE-2023-37395LOWCVSS 3.3≥ 5.0.0, ≤ 5.0.72024-12-11
CVE-2023-37395 [LOW] CWE-327 CVE-2023-37395: IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due t IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
cvelistv5nvd
CVE-2024-45098HIGHCVSS 8.1≥ 5.0.0, < 5.0.10≥ 5.0.0, ≤ 5.0.92024-09-05
CVE-2024-45098 [MEDIUM] CWE-650 CVE-2024-45098: IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
cvelistv5nvd