HTML Injection Vulnerability in IBM Aspera Faspex Affects Multiple Versions
CVE-2025-33138

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
22 May 2025

What is CVE-2025-33138?

IBM Aspera Faspex versions 5.0.0 through 5.0.12 are susceptible to an HTML injection vulnerability that enables a remote attacker to inject and execute malicious HTML code in the victim's web browser. This occurs when the injected code is viewed, potentially compromising user data and privacy within the security context of the hosting site. Users and administrators of affected versions are advised to apply the necessary security patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Aspera Faspex 5.0.0 <= 5.0.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.