CVE-2025-33137: IBM Aspera Faspex
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.
Affected products
- IBM Aspera Faspex: from 5.0.0, before 5.0.12.1 (fixed in 5.0.12.1)
Published 2025-05-22. Last modified 2026-06-17.