IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.

Project Subscriptions

Vendors Products
Aspera Orchestrator Subscribe
Advisories

No advisories yet.

Fixes

Solution

ProductVersionPlatformLink to FixIBM Aspera Orchestrator4.1.3Linux Link https://www.ibm.com/support/fixcentral/swg/selectFixes


Workaround

No workaround given by the vendor.

History

Wed, 11 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Title Multiple vulnerabilities in IBM Aspera Orchestrator
First Time appeared Ibm
Ibm aspera Orchestrator
Weaknesses CWE-598
CPEs cpe:2.3:a:ibm:aspera_orchestrator:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_orchestrator:4.1.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Orchestrator
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-11T14:09:47.903Z

Reserved: 2025-11-14T20:37:15.537Z

Link: CVE-2025-13219

cve-icon Vulnrichment

Updated: 2026-03-11T14:09:44.294Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-10T20:16:19.233

Modified: 2026-03-11T13:53:20.707

Link: CVE-2025-13219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-11T11:43:03Z

Weaknesses