CVE-2025-13213

IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
References
Link Resource
https://www.ibm.com/support/pages/node/7263083 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:aspera_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

12 Mar 2026, 15:19

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:aspera_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
First Time Linux
Ibm aspera Orchestrator
Ibm
Linux linux Kernel
References () https://www.ibm.com/support/pages/node/7263083 - () https://www.ibm.com/support/pages/node/7263083 - Vendor Advisory

11 Mar 2026, 13:52

Type Values Removed Values Added
Summary
  • (es) IBM Aspera Orchestrator 3.0.0 hasta 4.1.2 es vulnerable a la inyección de encabezados HTTP, causada por la validación inadecuada de la entrada por parte de los encabezados HOST. Esto podría permitir a un atacante llevar a cabo varios ataques contra el sistema vulnerable, incluyendo cross-site scripting, envenenamiento de caché o secuestro de sesión.

10 Mar 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 21:16

Updated : 2026-03-12 15:19


NVD link : CVE-2025-13213

Mitre link : CVE-2025-13213

CVE.ORG link : CVE-2025-13213


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • aspera_orchestrator
CWE
CWE-644

Improper Neutralization of HTTP Headers for Scripting Syntax