Sensitive Information Exposure in IBM Aspera Console
CVE-2025-13925
4.9MEDIUM
What is CVE-2025-13925?
The IBM Aspera Console version 3.4.7 has a vulnerability where it stores potentially sensitive information in log files. This information can be accessed by a local privileged user, posing a significant security risk. Organizations using this product should take immediate action to mitigate this exposure and review their logging practices.
Affected Version(s)
Aspera Console 3.4.7
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved