CVE-2025-36225: IBM Aspera Faspex
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
Affected products
- IBM Aspera Faspex: from 5.0.0, before 5.0.14 (fixed in 5.0.14)
Published 2025-10-09. Last modified 2026-10-08.