CVE-2025-13148

8.1

IBM · Aspera Orchestrator

IBM Aspera Orchestrator versions 4.0.0 through 4.1.0 contain an unverified password change vulnerability that allows authenticated users to modify the password of another user.

Executive summary

An authenticated user can bypass security controls to reset other user passwords in IBM Aspera Orchestrator, potentially leading to full account takeover.

Vulnerability

This vulnerability, identified as CWE-620, allows an authenticated user to change the password of any other user without knowing the original password. The flaw exists due to a lack of proper verification during the password change process.

Business impact

The ability for an authenticated user to reset another account's credentials poses a significant risk to data confidentiality and system integrity. With a CVSS score of 8.1, this high-severity flaw could allow an attacker to escalate privileges by targeting administrative accounts, potentially leading to unauthorized access to sensitive file transfer workflows and business-critical data.

Remediation

Immediate Action: Upgrade to IBM Aspera Orchestrator version 4.1.1 immediately as per the official vendor security advisory.

Proactive Monitoring: Review system authentication logs for unusual password change activities or patterns of rapid account modification.

Compensating Controls: Limit access to the orchestration interface to trusted users via network-level restrictions or VPNs until the patch is successfully applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the direct impact on user account security, this vulnerability presents an elevated risk to the integrity of the Aspera environment. Security teams should prioritize the upgrade to version 4.1.1 across all affected instances to eliminate the possibility of unauthorized password resets and subsequent account compromise.

More IBM CVEs

Sources