CVE-2025-36274
7.5IBM · Aspera HTTP Gateway
IBM Aspera HTTP Gateway versions 2.0.0 through 2.3.1 store sensitive information in cleartext, allowing unauthenticated users to access this data via easily obtainable files.
Executive summary
A critical information disclosure vulnerability in IBM Aspera HTTP Gateway allows unauthenticated attackers to access sensitive data, necessitating an immediate upgrade.
Vulnerability
This vulnerability involves the storage of sensitive information in cleartext within accessible files (CWE-319). An unauthenticated attacker can exploit this flaw to read sensitive data without requiring any prior system access or credentials.
Business impact
The exposure of sensitive information can lead to severe security breaches, including the compromise of credentials, configuration secrets, or proprietary data. Given the CVSS score of 7.5, this vulnerability represents a high risk because it is easily exploitable over the network by any unauthenticated actor. Failure to remediate could result in unauthorized data exfiltration and significant regulatory or operational exposure.
Remediation
Immediate Action: Upgrade IBM Aspera HTTP Gateway to version 2.3.2 immediately as specified in the IBM security bulletin.
Proactive Monitoring: Review system access logs for unusual file access patterns or unauthorized requests directed at sensitive configuration directories.
Compensating Controls: Implement network-level access controls to restrict access to the HTTP Gateway only to authorized IP addresses until the patch can be applied.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Organizations utilizing IBM Aspera HTTP Gateway must prioritize the transition to version 2.3.2. Because this vulnerability allows unauthenticated access to sensitive data, it should be treated as a high-priority remediation task to prevent unauthorized information disclosure. Apply the vendor-provided patch immediately to eliminate the risk of exploitation.
More IBM CVEs
Sources
Originally found and disclosed by jhon1231248e, per the CVE Program record.