← Back

CVE-2025-13481

nvd nist
Published: Dec 11, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: psirt@us.ibm.com (Secondary)

Description

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

Affected (1)

1 product
Aspera Orchestrator
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.0.0 to 4.1.1
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.