PT-2025-53588 · Ibm · Ibm Aspera Faspex

Published

2025-12-26

·

Updated

2025-12-29

·

CVE-2025-36230

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Aspera Faspex versions 5.0.0 through 5.0.14.1
Description The software is susceptible to HTML injection. A remote attacker can inject malicious HTML code that, when viewed, executes within the victim’s web browser in the security context of the hosting site.
Recommendations Update IBM Aspera Faspex to a version later than 5.0.14.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-36230

Affected Products

Ibm Aspera Faspex