CVE-2025-36229
IBM Aspera Faspex vulnerability analysis and mitigation

Overview

CVE-2025-36229 is an information disclosure vulnerability in IBM Aspera Faspex 5 that allows authenticated users to enumerate sensitive package information by iterating over package identifiers. It affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.14.1, with version 5.0.14.2 being the first patched release. The vulnerability was published on December 26, 2025, and received initial NVD analysis on December 29, 2025. NIST NVD assigns a CVSS v3.1 base score of 4.3 (Medium), while IBM's own CNA scoring rates it 3.1 (Low) (IBM Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), mapped to CAPEC-170 (Web Application Fingerprinting). An authenticated low-privilege user can systematically enumerate package identifiers within the Aspera Faspex application to discover sensitive metadata about file transfer packages that they should not have access to. The attack requires network access and valid credentials but no special privileges or user interaction, making it a straightforward enumeration attack against predictable or sequential package IDs (IBM Advisory, Red Hat CVE).

Impact

Successful exploitation allows a low-privilege authenticated attacker to access sensitive metadata about data packages — including potentially confidential information about file transfers, package contents, and recipient details — that they are not authorized to view. The impact is limited to confidentiality (no integrity or availability impact), but the enumeration capability could enable reconnaissance of organizational file transfer activity, potentially exposing sensitive business data or facilitating further targeted attacks (IBM Advisory, Red Hat CVE).

Exploitation steps

  1. Authentication: Obtain valid low-privilege credentials for the target IBM Aspera Faspex 5 instance (versions 5.0.0–5.0.14.1).
  2. Reconnaissance: Identify the API or web endpoint used to retrieve package information by package identifier (e.g., via the Faspex web interface or REST API).
  3. Enumeration: Systematically iterate over package identifiers (e.g., sequential integers or UUIDs) by sending authenticated requests to the package retrieval endpoint.
  4. Data collection: Collect returned metadata for each valid package identifier, including information about file transfers, senders, recipients, and package contents that the attacker is not authorized to access.
  5. Analysis: Analyze the harvested metadata for sensitive information useful for further reconnaissance or targeted attacks (IBM Advisory).

Indicators of compromise

  • Network: Unusually high volume of authenticated API or HTTP requests to package retrieval endpoints from a single user account or IP address, particularly with sequential or systematically varying package identifier values.
  • Logs: Application access logs showing a single authenticated user querying a large number of distinct package IDs in a short time window; repeated 200 OK responses to package detail requests from accounts that do not own those packages.
  • Behavioral: A low-privilege user account accessing package metadata far beyond their normal usage pattern or accessing packages belonging to other users.

Mitigation and workarounds

IBM has released IBM Aspera Faspex 5 version 5.0.14.2 to address this vulnerability; upgrading to this version or later is the recommended remediation. As interim measures, organizations should implement strict access controls to minimize unnecessary user privileges, monitor authentication and access logs for suspicious enumeration patterns, and regularly audit user account permissions. No configuration-based workaround has been published by IBM (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM Aspera Faspex vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36227MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesMar 10, 2026
CVE-2025-36226MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesMar 10, 2026
CVE-2025-36230MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025
CVE-2025-36229MEDIUM4.3
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025
CVE-2025-36228LOW3.8
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management