CVE-2025-36228
Inconsistent Permission Vulnerability in IBM Aspera Faspex
Publication date: 2025-12-26
Last updated on: 2025-12-26
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | aspera_faspex | 5.0.0 |
| ibm | aspera_faspex | 5.0.14.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-279 | While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in IBM Aspera Faspex versions 5.0.0 through 5.0.14.1 allows inconsistent permissions between the user interface and the backend API. This inconsistency can enable users to access features that appear disabled in the user interface, potentially leading to misuse.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to features that should be disabled, potentially allowing misuse of the system. This could result in unauthorized actions or data exposure due to the mismatch in permission enforcement between the user interface and backend API.