Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing the vulnerabilities now by upgrading to Faspex 5.0.13.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23212 | IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7241007 |
|
Wed, 06 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:aspera_faspex:*:*:*:*:*:*:*:* |
Thu, 31 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 31 Jul 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms. | |
| Title | IBM Aspera Faspex session fixation | |
| First Time appeared |
Ibm
Ibm aspera Faspex |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:aspera_faspex:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.12.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.12:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.6:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.7:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.8:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Faspex |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-07-31T17:55:19.229Z
Reserved: 2025-04-15T21:16:10.568Z
Link: CVE-2025-36040
Updated: 2025-07-31T13:39:36.885Z
Status : Analyzed
Published: 2025-07-31T00:15:26.580
Modified: 2025-08-06T16:53:32.810
Link: CVE-2025-36040
No data.
OpenCVE Enrichment
No data.
EUVD