CVE-2025-36040: IBM Aspera Faspex session fixation
IBM Aspera Faspex 5 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36040?
The severity of CVE-2025-36040 is classified as high due to the potential for unauthorized actions by authenticated users.
How do I fix CVE-2025-36040?
To fix CVE-2025-36040, upgrade IBM Aspera Faspex to version 5.0.12.2 or later.
Who is affected by CVE-2025-36040?
CVE-2025-36040 affects all authenticated users of IBM Aspera Faspex versions 5.0.0 to 5.0.12.1.
What types of actions can be performed due to CVE-2025-36040?
Due to CVE-2025-36040, authenticated users may perform unauthorized actions that should be restricted by server-side controls.
What software is vulnerable to CVE-2025-36040?
IBM Aspera Faspex versions 5.0.0 through 5.0.12.1 are vulnerable to CVE-2025-36040.