CVE-2025-33136: IBM Aspera Faspex data modification
IBM Aspera Faspex 5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33136?
The severity of CVE-2025-33136 is classified as high due to its potential to allow unauthorized actions and sensitive data exposure.
How do I fix CVE-2025-33136?
To fix CVE-2025-33136, upgrade IBM Aspera Faspex to version 5.0.13 or later where the vulnerability has been addressed.
Who is affected by CVE-2025-33136?
Authenticated users of IBM Aspera Faspex versions 5.0.0 through 5.0.12 are affected by CVE-2025-33136.
What type of vulnerability is CVE-2025-33136?
CVE-2025-33136 is an information disclosure and privilege escalation vulnerability.
What are the potential impacts of CVE-2025-33136?
The potential impacts of CVE-2025-33136 include unauthorized access to sensitive information and the ability to perform actions on behalf of another user.