PT-2026-24404 · Ibm · Ibm Aspera Orchestrator

Published

2026-03-10

·

Updated

2026-03-10

·

CVE-2025-13213

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Aspera Orchestrator versions 3.0.0 through 4.1.2
Description The software is susceptible to HTTP header injection due to inadequate input validation of the HOST headers. This could enable an attacker to perform various attacks against the system, including cross-site scripting, cache poisoning, or session hijacking.
Recommendations Update IBM Aspera Orchestrator to a version later than 4.1.2.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-13213

Affected Products

Ibm Aspera Orchestrator