2025-12-26 14:11CVE-2025-36228ibm
PUBLISHED5.2ApplicationCWE-279

Incorrect Execution-Assigned Permissions in IBM Aspera Faspex

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.

Problem type

Affected products

IBM

Aspera Faspex 5

<= 5.0.14.1 - AFFECTED

References

GitHub Security Advisories

GHSA-cqcr-6gvh-8xmg

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user...

https://github.com/advisories/GHSA-cqcr-6gvh-8xmg

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2025-36228
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2025-36228",
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "dateUpdated": "2025-12-26T15:15:06.304Z",
    "dateReserved": "2025-04-15T21:16:41.802Z",
    "datePublished": "2025-12-26T14:11:45.492Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm",
        "dateUpdated": "2025-12-26T14:11:45.492Z"
      },
      "title": "Incorrect Execution-Assigned Permissions in IBM Aspera Faspex",
      "descriptions": [
        {
          "lang": "en",
          "value": "IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, potentially leading to misuse.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "IBM",
          "product": "Aspera Faspex 5",
          "cpes": [
            "cpe:2.3:a:ibm:aspera_faspex_5:5.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:aspera_faspex_5:5.0.14.1:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "5.0.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "5.0.14.1"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-279 Incorrect Execution-Assigned Permissions",
              "cweId": "CWE-279",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7255331",
          "tags": [
            "vendor-advisory",
            "patch"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "availabilityImpact": "NONE",
            "baseScore": 3.8,
            "baseSeverity": "LOW"
          }
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "IBM strongly recommends addressing the vulnerabilities now by upgrading to Faspex 5.0.14 available from the link below.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p></p><div>IBM strongly recommends addressing the vulnerabilities now by upgrading to Faspex 5.0.14 available from the link below.</div><p></p>"
            }
          ]
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2025-12-26T15:15:06.304Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}