Client-Side Security Flaws in IBM Aspera Faspex Products
CVE-2025-33137
8.8HIGH
What is CVE-2025-33137?
IBM Aspera Faspex versions 5.0.0 through 5.0.12 have a client-side security flaw that may enable an authenticated user to gain access to sensitive information or execute actions impersonating another user. This issue arises from inadequate server-side security measures being enforced client-side, allowing for potential data breaches and unauthorized access.
Affected Version(s)
Aspera Faspex 5.0.0 <= 5.0.12