4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
IBM Aspera 5.0.0 through 5.0.13.1
could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
Basic Information
ID
CVE-2025-36225
Source
ibm
Published
Oct 9, 2025 at 13:56
Affected Product
Vendor
IBM
Product
Aspera Faspex
Version
5.0.0
Affected Versions
IBM Aspera Faspex 5.0.0