CVE-2025-13481HIGH 8.8EPSS p32.0%
CVE-2025-13481CVE-2025-13481
Description
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.40% probability of exploitation · percentile 32.0% · 2026-06-19T12:03:05Z |
| Published | 2025-12-11 |
| Last modified | 2025-12-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-78 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.