CVE-2025-13214: IBM Aspera Orchestrator

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Affected products

  • IBM Aspera Orchestrator: from 4.0.0, before 4.1.1 (fixed in 4.1.1)

Published 2025-12-11. Last modified 2026-10-07.