cbcvebase.
CVE-2025-33137
published 2025-05-22

CVE-2025-33137: IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another…

PriorityP348high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.29%
20.6th percentile
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmaspera_faspex>= 5.0.0 < 5.0.12.15.0.12.1
ibmaspera_faspex5.0.0 – 5.0.12
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.