IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7254434 |
|
History
Thu, 11 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Title | IBM Aspera Orchestrator Command Injection | |
| First Time appeared |
Ibm
Ibm aspera Orchestrator |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:aspera_orchestrator:4.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_orchestrator:4.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Orchestrator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-12-11T19:47:10.233Z
Updated: 2025-12-11T20:34:53.985Z
Reserved: 2025-11-20T15:07:48.479Z
Link: CVE-2025-13481
Updated: 2025-12-11T20:28:37.800Z
Status : Undergoing Analysis
Published: 2025-12-11T20:15:53.230
Modified: 2025-12-12T15:18:13.390
Link: CVE-2025-13481
No data.
ReportizFlow