Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Aspera Faspex
Total 46 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-3423 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2026-06-17 N/A 5.4 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2025-36230 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 5.4 MEDIUM
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
CVE-2025-36229 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 3.1 LOW
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
CVE-2025-36228 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 3.8 LOW
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.
CVE-2025-36227 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2026-06-17 N/A 5.4 MEDIUM
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
CVE-2025-36226 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2026-06-17 N/A 5.4 MEDIUM
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2025-36225 3 Ibm, Linux, Microsoft 3 Aspera Faspex, Linux Kernel, Windows 2026-06-17 N/A 4.3 MEDIUM
IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
CVE-2025-36171 3 Ibm, Linux, Microsoft 3 Aspera Faspex, Linux Kernel, Windows 2026-06-17 N/A 4.9 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption.
CVE-2025-36040 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 6.5 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
CVE-2025-36039 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 6.5 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
CVE-2025-33138 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2026-06-17 N/A 5.4 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
CVE-2025-33137 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2026-06-17 N/A 7.1 HIGH
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.
CVE-2025-33136 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2026-06-17 N/A 7.1 HIGH
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
CVE-2024-45098 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 6.8 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
CVE-2024-45097 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 5.9 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
CVE-2024-45096 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 6.5 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.
CVE-2023-37413 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 5.3 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
CVE-2023-37412 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 4.4 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
CVE-2023-37411 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 4.8 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260139.
CVE-2023-37401 3 Ibm, Linux, Microsoft 3 Aspera Faspex, Linux Kernel, Windows 2026-06-17 N/A 5.3 MEDIUM
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.