IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7234114 |
|
History
Fri, 30 May 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:ibm:aspera_faspex:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel |
Thu, 22 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 May 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data. | |
| Title | IBM Aspera Faspex data modification | |
| First Time appeared |
Ibm
Ibm aspera Faspex |
|
| Weaknesses | CWE-471 | |
| CPEs | cpe:2.3:a:ibm:aspera_faspex:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_faspex:5.0.12:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Faspex |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-05-22T16:14:02.649Z
Updated: 2025-08-26T15:04:47.668Z
Reserved: 2025-04-15T17:51:21.699Z
Link: CVE-2025-33136
Updated: 2025-05-22T17:42:45.497Z
Status : Analyzed
Published: 2025-05-22T17:15:23.420
Modified: 2025-05-30T01:19:40.167
Link: CVE-2025-33136
No data.