CVE-2025-13219
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Affected (1)
Products: Ibm: Aspera Orchestrator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 4.1.3 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
References (1)
Timeline
No history available yet.