Client-Side Security Flaws in IBM Aspera Faspex Products
CVE-2025-33137

8.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
22 May 2025

What is CVE-2025-33137?

IBM Aspera Faspex versions 5.0.0 through 5.0.12 have a client-side security flaw that may enable an authenticated user to gain access to sensitive information or execute actions impersonating another user. This issue arises from inadequate server-side security measures being enforced client-side, allowing for potential data breaches and unauthorized access.

Affected Version(s)

Aspera Faspex 5.0.0 <= 5.0.12

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.