CVE-2025-33137

HIGH

IBM Aspera Faspex <5.0.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7234114

Scores

CVSS v3 7.1
EPSS 0.0029
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-602
Status published
Products (1)
ibm/aspera_faspex 5.0.0 - 5.0.12.1
Published May 22, 2025
Tracked Since Feb 18, 2026