IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
CVE ID: CVE-2025-33136
CVSS Base Severity: HIGH
CVSS Base Score: 7.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Vendor: IBM
Product: Aspera Faspex
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 8.11% (scored less or equal to compared to others)
EPSS Date: 2025-06-14 (when was this score calculated)