CVE-2025-13219 PUBLISHED

Multiple vulnerabilities in IBM Aspera Orchestrator

Assigner: ibm
Reserved: 14.11.2025 Published: 10.03.2026 Updated: 11.03.2026

IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.9

Product Status

Vendor IBM
Product Aspera Orchestrator
Versions
  • affected from 3.0.0 to 4.1.2 (incl.)

Solutions

ProductVersionPlatformLink to FixIBM Aspera Orchestrator4.1.3Linux Link https://www.ibm.com/support/fixcentral/swg/selectFixes

References

Problem Types

  • CWE-598 Use of GET Request Method With Sensitive Query Strings CWE