Password Management Flaw in IBM Aspera Orchestrator Affects Multiple Versions
CVE-2025-13148

8.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
11 December 2025

What is CVE-2025-13148?

A vulnerability in IBM Aspera Orchestrator allows authenticated users to change the passwords of other users without prior knowledge of those passwords. This flaw could lead to unauthorized access and manipulation of user accounts, presenting a significant security risk for organizations relying on affected versions of the product. Users are advised to consult IBM's vendor advisory for patches and mitigations.

Affected Version(s)

Aspera Orchestrator 4.0.0 <= 4.1.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-13148 : Password Management Flaw in IBM Aspera Orchestrator Affects Multiple Versions