CVE-2025-33136

HIGH

IBM Aspera Faspex <5.0.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7234114

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-471
Status published
Products (1)
ibm/aspera_faspex 5.0.0 - 5.0.12.1
Published May 22, 2025
Tracked Since Feb 18, 2026