CVE-2025-13481High· 8.8▾ TwilightIBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
aspera_orchestrator >= 4.0.0, < 4.1.1Upgrade past the affected range:
aspera_orchestrator 4.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13211Medium· 5.3IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
CVE-2025-13214High· 7.6IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection
CVE-2025-13148High· 8.1IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.
CVE-2026-84440High· 7.5IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality
CVE-2026-84436Critical· 9.1IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
CVE-2026-84422High· 7.2IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.