CVE-2025-33137: IBM Aspera Faspex data modification
IBM Aspera Faspex 5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33137?
The severity of CVE-2025-33137 is considered high due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2025-33137?
To fix CVE-2025-33137, update IBM Aspera Faspex to the latest version beyond 5.0.12 where the vulnerability is addressed.
Who is affected by CVE-2025-33137?
CVE-2025-33137 affects authenticated users of IBM Aspera Faspex versions 5.0.0 through 5.0.12.
What are the potential risks of CVE-2025-33137?
The potential risks of CVE-2025-33137 include unauthorized actions being performed on behalf of another user, leading to data breaches.
What products are impacted by CVE-2025-33137?
CVE-2025-33137 impacts IBM Aspera Faspex versions 5.0.0 to 5.0.12, allowing for sensitive information exposure.