CVE-2025-36228
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
Scoring
- Severity
- LOW
- CVSS base score
- 3.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-279
- Published
- 2025-12-26
- Last modified
- 2026-03-13
Affected products
- IBM Aspera Faspex 5
Weakness type
Related vulnerabilities
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4948 — Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
- CVE-2026-20062 — A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in...
- CVE-2025-12801 — Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
- CVE-2025-14025 — Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
- CVE-2025-13663 — Quartus Prime Pro Edition Installer Advisory
- CVE-2024-25621 — containerd affected by a local privilege escalation via wide permissions on CRI directory
- CVE-2025-30001 — Apache StreamPark: Authenticated users can trigger remote command execution