cbcvebase.

Ibm Aspera Faspex vulnerabilities

46 known vulnerabilities affecting ibm/aspera_faspex.

Total CVEs
46
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH12MEDIUM29LOW2

Vulnerabilities

Page 3 of 3
CVE-2025-36225P4MEDIUMCVSS 4.3≥ 5.0.0, < 5.0.14≥ 5.0.0, ≤ 5.0.13.12025-10-09
CVE-2025-36225 [MEDIUM] CWE-203 CVE-2025-36225: IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
nvd
CVE-2025-36171P4MEDIUMCVSS 4.9≥ 5.0.0, < 5.0.14≥ 5.0.0, ≤ 5.0.13.12025-10-09
CVE-2025-36171 [MEDIUM] CWE-770 CVE-2025-36171: IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
nvd
CVE-2025-36229P4MEDIUMCVSS 4.3≥ 5.0.0, < 5.0.14.22025-12-26
CVE-2025-36229 [MEDIUM] CWE-497 CVE-2025-36229: IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive in IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
nvd
CVE-2023-37397P4MEDIUMCVSS 4.4≥ 5.0.0, ≤ 5.0.72024-04-19
CVE-2023-37397 [MEDIUM] CWE-326 CVE-2023-37397: IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive informa IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.
nvd
CVE-2025-36228P4LOWCVSS 3.8≥ 5.0.0, < 5.0.14.22025-12-26
CVE-2025-36228 [LOW] CWE-279 CVE-2025-36228: IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user inter IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
nvd
CVE-2023-37395P4LOWCVSS 3.3≥ 5.0.0, ≤ 5.0.72024-12-11
CVE-2023-37395 [LOW] CWE-327 CVE-2023-37395: IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due t IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
nvd