
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36229 is an information disclosure vulnerability in IBM Aspera Faspex 5 that allows authenticated users to enumerate sensitive package information by iterating over package identifiers. It affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.14.1, with version 5.0.14.2 being the first patched release. The vulnerability was published on December 26, 2025, and received initial NVD analysis on December 29, 2025. NIST NVD assigns a CVSS v3.1 base score of 4.3 (Medium), while IBM's own CNA scoring rates it 3.1 (Low) (IBM Advisory, Red Hat CVE).
The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), mapped to CAPEC-170 (Web Application Fingerprinting). An authenticated low-privilege user can systematically enumerate package identifiers within the Aspera Faspex application to discover sensitive metadata about file transfer packages that they should not have access to. The attack requires network access and valid credentials but no special privileges or user interaction, making it a straightforward enumeration attack against predictable or sequential package IDs (IBM Advisory, Red Hat CVE).
Successful exploitation allows a low-privilege authenticated attacker to access sensitive metadata about data packages — including potentially confidential information about file transfers, package contents, and recipient details — that they are not authorized to view. The impact is limited to confidentiality (no integrity or availability impact), but the enumeration capability could enable reconnaissance of organizational file transfer activity, potentially exposing sensitive business data or facilitating further targeted attacks (IBM Advisory, Red Hat CVE).
IBM has released IBM Aspera Faspex 5 version 5.0.14.2 to address this vulnerability; upgrading to this version or later is the recommended remediation. As interim measures, organizations should implement strict access controls to minimize unnecessary user privileges, monitor authentication and access logs for suspicious enumeration patterns, and regularly audit user account permissions. No configuration-based workaround has been published by IBM (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."