IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7254434 |
|
History
Mon, 15 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel |
|
| CPEs | cpe:2.3:a:ibm:aspera_orchestrator:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel |
Thu, 11 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Title | IBM Aspera Orchestrator Command Injection | |
| First Time appeared |
Ibm
Ibm aspera Orchestrator |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:ibm:aspera_orchestrator:4.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_orchestrator:4.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Orchestrator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-12-11T20:34:53.985Z
Reserved: 2025-11-20T15:07:48.479Z
Link: CVE-2025-13481
Updated: 2025-12-11T20:28:37.800Z
Status : Analyzed
Published: 2025-12-11T20:15:53.230
Modified: 2025-12-15T19:02:24.790
Link: CVE-2025-13481
No data.