CVE-2025-36230
- EPSS 0.04%
- Veröffentlicht 26.12.2025 14:22:46
- Zuletzt bearbeitet 29.12.2025 17:42:46
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
CVE-2025-36229
- EPSS 0.03%
- Veröffentlicht 26.12.2025 14:15:03
- Zuletzt bearbeitet 29.12.2025 18:10:45
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
CVE-2025-36228
- EPSS 0.03%
- Veröffentlicht 26.12.2025 14:11:45
- Zuletzt bearbeitet 29.12.2025 18:15:10
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
CVE-2025-36171
- EPSS 0.06%
- Veröffentlicht 09.10.2025 14:15:54
- Zuletzt bearbeitet 14.10.2025 20:18:22
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
CVE-2025-36225
- EPSS 0.04%
- Veröffentlicht 09.10.2025 13:56:19
- Zuletzt bearbeitet 14.10.2025 20:18:48
IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
CVE-2023-37401
- EPSS 0.04%
- Veröffentlicht 09.10.2025 13:54:38
- Zuletzt bearbeitet 14.10.2025 20:18:35
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.
CVE-2025-36040
- EPSS 0.03%
- Veröffentlicht 30.07.2025 23:48:52
- Zuletzt bearbeitet 06.08.2025 16:53:32
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
CVE-2025-36039
- EPSS 0.03%
- Veröffentlicht 30.07.2025 23:47:25
- Zuletzt bearbeitet 06.08.2025 16:54:00
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
CVE-2025-33138
- EPSS 0.03%
- Veröffentlicht 22.05.2025 16:37:28
- Zuletzt bearbeitet 30.05.2025 01:19:08
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
CVE-2025-33137
- EPSS 0.04%
- Veröffentlicht 22.05.2025 16:36:04
- Zuletzt bearbeitet 30.05.2025 01:19:24
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.