PT-2025-50695 · Ibm+1 · Ibm Aspera Orchestrator+1

Published

2025-12-11

·

Updated

2025-12-11

·

CVE-2025-13481

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Aspera Orchestrator versions 4.0.0 through 4.1.0
Description Improper validation of user supplied input allows an authenticated user to execute arbitrary commands with elevated privileges on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13481

Affected Products

Ibm Aspera Orchestrator
Snowflake Connector For Python