cbcvebase.
CVE-2025-13148
published 2025-12-11

CVE-2025-13148: IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmaspera_orchestrator>= 4.0.0 < 4.1.14.1.1
ibmaspera_orchestrator4.0.0 – 4.1.0