Password Management Flaw in IBM Aspera Orchestrator Affects Multiple Versions
CVE-2025-13148
8.1HIGH
What is CVE-2025-13148?
A vulnerability in IBM Aspera Orchestrator allows authenticated users to change the passwords of other users without prior knowledge of those passwords. This flaw could lead to unauthorized access and manipulation of user accounts, presenting a significant security risk for organizations relying on affected versions of the product. Users are advised to consult IBM's vendor advisory for patches and mitigations.
Affected Version(s)
Aspera Orchestrator 4.0.0 <= 4.1.0