CVE-2025-13481

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
References
Link Resource
https://www.ibm.com/support/pages/node/7254434 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:aspera_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

15 Dec 2025, 19:02

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7254434 - () https://www.ibm.com/support/pages/node/7254434 - Vendor Advisory
CPE cpe:2.3:a:ibm:aspera_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
First Time Linux
Ibm aspera Orchestrator
Ibm
Linux linux Kernel

11 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 20:15

Updated : 2025-12-15 19:02


NVD link : CVE-2025-13481

Mitre link : CVE-2025-13481

CVE.ORG link : CVE-2025-13481


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • aspera_orchestrator
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')