IBM Product Update Advisory

IBM Product Update Advisory

Overview

 

We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-33136, CVE-2025-33137

 

Aspera Faspex 5 Versions: 5.0.0 and later to 5.0.12 and earlier

 

 

Resolved Vulnerabilities

 

Immutable Data Modification Vulnerability in IBM Aspera Faspex 5 (CVE-2025-33136)
Security Enforcement Not Enforced Vulnerability in IBM Aspera Faspex 5 (CVE-2025-33137)

 

 

Vulnerability Patches

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

 

CVE-2025-33136, CVE-2025-33137

 

Aspera Faspex 5 Version: 5.0.12.1

 

 

References

 

[1] Security Bulletin: IBM Aspera Faspex is affected by user input sanitization and HTML injection vulnerabilities
https://www.ibm.com/support/pages/node/7234114