Back

HIGH

IBM Aspera Faspex data modification

Published May 22, 2025

Description

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerabilities now by upgrading the container images to 5.0.12.1 available from IBM Container Registry

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published May 22, 2025
Updated Aug 26, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated May 22, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published May 22, 2025
Updated Aug 26, 2025
Exploited since n/a
EUVD-2025-16173