CVE-2025-13148: IBM Aspera Orchestrator
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.
Affected products
- IBM Aspera Orchestrator: from 4.0.0, before 4.1.1 (fixed in 4.1.1)
Published 2025-12-11. Last modified 2026-10-07.