Information Disclosure Vulnerability in IBM Aspera Orchestrator
CVE-2025-13219
5.9MEDIUM
What is CVE-2025-13219?
The IBM Aspera Orchestrator versions 3.0.0 through 4.1.2 expose sensitive information through the storage of URL parameters. This flaw can lead to unauthorized access to confidential data if those URLs are exposed via server logs, referrer headers, or browser history, potentially allowing malicious actors to exploit the information for nefarious purposes. Organizations using affected versions are encouraged to review their exposure to this vulnerability and implement the necessary mitigations, as outlined in the vendor advisory.
Affected Version(s)
Aspera Orchestrator 3.0.0 <= 4.1.2