CVE-2025-36225: IBM Aspera Faspex information disclosure
IBM Aspera 5.0.0 through 5.0.13.1
could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
Other sources
IBM Aspera Faspex 5 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36225?
The severity of CVE-2025-36225 has not been publicly rated, but it relates to the potential disclosure of sensitive user information.
How do I fix CVE-2025-36225?
To fix CVE-2025-36225, update IBM Aspera Faspex to a version above 5.0.13.1.
What versions of IBM Aspera are affected by CVE-2025-36225?
IBM Aspera Faspex versions from 5.0.0 to 5.0.13.1 are affected by CVE-2025-36225.
What kind of information could be leaked due to CVE-2025-36225?
CVE-2025-36225 could potentially disclose sensitive user information to authenticated users.
Is CVE-2025-36225 a critical vulnerability?
While not rated as critical, CVE-2025-36225 poses a risk by allowing information disclosure which could have serious implications.