
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36228 is a permission inconsistency vulnerability in IBM Aspera Faspex 5 that allows authenticated high-privilege users to access backend API features that appear disabled in the user interface, potentially leading to misuse. It affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.14.1 (fixed in 5.0.14.2). The CVE was published on December 26, 2025, with initial NVD analysis completed December 29, 2025. It carries a CVSS v3.1 base score of 3.8 (Low), assigned by IBM Corporation (IBM Advisory, Feedly).
The root cause is classified as CWE-279 (Incorrect Execution-Assigned Permissions), where the application fails to enforce consistent access controls between its user interface layer and the underlying backend API. When certain features are disabled via the UI, the corresponding API endpoints remain accessible, allowing users with high-privilege accounts to invoke those features directly through API calls, bypassing the apparent UI restrictions. No public technical write-ups or proof-of-concept code have been identified for this vulnerability (IBM Advisory, Feedly).
Successful exploitation results in limited confidentiality and integrity impacts — specifically, a high-privilege authenticated attacker could access or manipulate features that should be restricted, potentially exposing sensitive operations or data within the Aspera Faspex file transfer platform. Availability is not impacted. The scope is unchanged, meaning exploitation is confined to the affected application and does not directly enable lateral movement to other systems (IBM Advisory, Feedly).
IBM has released version 5.0.14.2 of Aspera Faspex 5, which addresses this vulnerability. Organizations should upgrade to version 5.0.14.2 or later as the primary remediation. As interim measures, administrators should audit and tighten user permissions, monitor backend API access logs for unexpected feature invocations, and implement strict access controls to limit high-privilege account usage (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."