VulnSea

aspera_orchestrator vulnerabilities

CVEs whose affected-version data names the aspera_orchestrator package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2025-13481High· 8.8
10mo ago

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

▾ Twilightibm · aspera_orchestratorEPSS 0.48%via NVD
CVE-2025-13214High· 7.6
10mo ago

IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection

IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

▾ Twilightibm · aspera_orchestratorEPSS 0.36%via NVD
CVE-2025-13211Medium· 5.3
10mo ago

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

▾ Sunlitibm · aspera_orchestratorEPSS 0.36%via NVD
CVE-2025-13148High· 8.1
10mo ago

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

▾ Twilightibm · aspera_orchestratorEPSS 0.28%via NVD
aspera_orchestrator vulnerabilities (CVEs) · VulnSea