IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
History

Wed, 11 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Title Multiple vulnerabilities in IBM Aspera Orchestrator
First Time appeared Ibm
Ibm aspera Orchestrator
Weaknesses CWE-598
CPEs cpe:2.3:a:ibm:aspera_orchestrator:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_orchestrator:4.1.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Orchestrator
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-03-10T20:08:20.129Z

Updated: 2026-03-11T14:09:47.903Z

Reserved: 2025-11-14T20:37:15.537Z

Link: CVE-2025-13219

cve-icon Vulnrichment

Updated: 2026-03-11T14:09:44.294Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-10T20:16:19.233

Modified: 2026-03-11T13:53:20.707

Link: CVE-2025-13219

cve-icon Redhat

No data.