CVE Vulnerabilities

CVE-2025-33136

Modification of Assumed-Immutable Data (MAID)

Published: May 22, 2025 | Modified: May 30, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.

Weakness

The product does not properly protect an assumed-immutable element from being modified by an attacker.

Affected Software

Name Vendor Start Version End Version
Aspera_faspex Ibm 5.0.0 (including) 5.0.12.1 (excluding)

Potential Mitigations

References