Security Advisory

CVE-2025-13148

8.1
HIGH

Vulnerability Description

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.
Published Date December 11, 2025
Official Source NIST NVD Advisory