Security Advisory
CVE-2025-13148
8.1
HIGH
Vulnerability Description
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.
Published Date
December 11, 2025
Official Source
NIST NVD Advisory