IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
History

Tue, 10 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Title Multiple vulnerabilities in IBM Aspera Orchestrator
First Time appeared Ibm
Ibm aspera Orchestrator
Weaknesses CWE-598
CPEs cpe:2.3:a:ibm:aspera_orchestrator:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_orchestrator:4.1.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Orchestrator
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-10T20:10:12.623Z

Reserved: 2025-11-14T20:37:15.537Z

Link: CVE-2025-13219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-10T20:16:19.233

Modified: 2026-03-10T20:16:19.233

Link: CVE-2025-13219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.