CVE-2025-13460: IBM Aspera Console

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.

Affected products

  • IBM Aspera Console: from 3.3.0, before 3.4.9 (fixed in 3.4.9)

Published 2026-03-16. Last modified 2026-06-17.