Sensitive Information Exposure in IBM Aspera Console
CVE-2025-13925

4.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
20 January 2026

What is CVE-2025-13925?

The IBM Aspera Console version 3.4.7 has a vulnerability where it stores potentially sensitive information in log files. This information can be accessed by a local privileged user, posing a significant security risk. Organizations using this product should take immediate action to mitigate this exposure and review their logging practices.

Affected Version(s)

Aspera Console 3.4.7

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.