CVE-2025-36274: IBM Aspera HTTP Gateway

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.

Affected products

  • IBM Aspera HTTP Gateway: from 2.0.0, before 2.3.2 (fixed in 2.3.2)

Published 2025-09-26. Last modified 2026-06-17.