CVE-2025-13214

7.6

IBM · Aspera Orchestrator

IBM Aspera Orchestrator versions 4.0.0 through 4.1.0 are vulnerable to SQL injection, allowing authenticated remote attackers to manipulate back-end database information.

Executive summary

A critical SQL injection vulnerability in IBM Aspera Orchestrator 4.0.0 through 4.1.0 allows authenticated remote attackers to compromise the integrity and confidentiality of back-end database information.

Vulnerability

This vulnerability is a SQL injection flaw (CWE-89) triggered by the improper neutralization of special elements in SQL commands. An authenticated remote attacker can inject crafted SQL statements to view, modify, or delete data within the underlying database.

Business impact

The ability to manipulate the back-end database poses a significant risk to data confidentiality, integrity, and availability. With a CVSS score of 7.6, this vulnerability warrants high priority as it could lead to unauthorized data exfiltration or the destruction of critical operational records, potentially causing severe service disruption or regulatory compliance failures.

Remediation

Immediate Action: Upgrade to IBM Aspera Orchestrator version 4.1.1 or later to fully remediate the vulnerability.

Proactive Monitoring: Review database access logs for unusual queries or unauthorized attempts to access or modify data tables.

Compensating Controls: Implement a Web Application Firewall (WAF) with SQL injection protection rules to inspect and block malicious traffic targeting the application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for database compromise, organizations should prioritize the deployment of the 4.1.1 patch. While the vulnerability requires an authenticated attacker, internal threats or compromised user credentials make this a high-risk vector that must be addressed immediately to prevent data loss or manipulation.

More IBM CVEs

Sources