CVE-2025-33138: IBM Aspera Faspex HTML injection
IBM Aspera Faspex 5 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33138?
CVE-2025-33138 has a high severity rating due to the potential for remote code execution via HTML injection.
How do I fix CVE-2025-33138?
To fix CVE-2025-33138, you should update IBM Aspera Faspex to version 5.0.12 or later.
What causes CVE-2025-33138?
CVE-2025-33138 is caused by insufficient input validation allowing HTML code injection in IBM Aspera Faspex.
Who is impacted by CVE-2025-33138?
Users of IBM Aspera Faspex versions 5.0.0 through 5.0.12 are impacted by CVE-2025-33138.
What type of vulnerability is CVE-2025-33138?
CVE-2025-33138 is classified as an HTML injection vulnerability.