CVE-2025-36039: IBM Aspera Faspex bypass security
IBM Aspera Faspex 5 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36039?
CVE-2025-36039 has a moderate severity rating due to its potential for unauthorized actions by authenticated users.
How do I fix CVE-2025-36039?
To fix CVE-2025-36039, upgrade IBM Aspera Faspex to version 5.0.12.2 or later.
Who is affected by CVE-2025-36039?
CVE-2025-36039 affects authenticated users of IBM Aspera Faspex versions 5.0.0 through 5.0.12.1.
What type of vulnerability is CVE-2025-36039?
CVE-2025-36039 is a client-side security vulnerability allowing unauthorized actions.
Can CVE-2025-36039 be exploited remotely?
CVE-2025-36039 requires authentication, hence it cannot be exploited by unauthenticated remote attackers.