CVE-2025-33137

HIGH

IBM Aspera Faspex <5.0.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-602
Status published
Products (1)
ibm/aspera_faspex 5.0.0 - 5.0.12.1
Published May 22, 2025
Tracked Since Feb 18, 2026