Information Disclosure Vulnerability in IBM Aspera Orchestrator
CVE-2025-13219

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
10 March 2026

What is CVE-2025-13219?

The IBM Aspera Orchestrator versions 3.0.0 through 4.1.2 expose sensitive information through the storage of URL parameters. This flaw can lead to unauthorized access to confidential data if those URLs are exposed via server logs, referrer headers, or browser history, potentially allowing malicious actors to exploit the information for nefarious purposes. Organizations using affected versions are encouraged to review their exposure to this vulnerability and implement the necessary mitigations, as outlined in the vendor advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Aspera Orchestrator 3.0.0 <= 4.1.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.