VendorsIBMaspera_orchestratorall versions
Vulnerabilities

IBM Aspera Orchestrator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-37407
IBM Aspera Orchestrator command execution
Published 2024-05-03 · Analyzed
8.8EPSS 0.009
CVE-2025-13481
IBM Aspera Orchestrator Command Injection
Published 2025-12-11 · Analyzed
8.8EPSS 0.005
CVE-2025-13214
IBM Aspera Orchestrator SQL Injection
Published 2025-12-11 · Analyzed
8.8EPSS 0.004
CVE-2025-13148
IBM Aspera Orchestrator Unverified Password Change
Published 2025-12-11 · Analyzed
8.1EPSS 0.003
CVE-2025-13219
Multiple vulnerabilities in IBM Aspera Orchestrator
Published 2026-03-10 · Analyzed
7.5EPSS 0.003
CVE-2025-13211
IBM Aspera Orchestrator Denial of Service
Published 2025-12-11 · Analyzed
6.5EPSS 0.004
CVE-2023-38001
IBM Aspera Orchestrator cross-site request forgery
Published 2024-07-30 · Modified
6.5EPSS 0.003
CVE-2023-26288
IBM Aspera Orchestrator session fixation
Published 2024-07-30 · Modified
5.5EPSS 0.002
CVE-2023-26289
IBM Aspera Orchestrator HTTP header injection
Published 2024-07-30 · Modified
5.4EPSS 0.003
CVE-2025-13213
Multiple vulnerabilities in IBM Aspera Orchestrator
Published 2026-03-10 · Analyzed
5.4EPSS 0.002
CVE-2023-27283
IBM Aspera Orchestrator information disclosure
Published 2024-05-04 · Analyzed
5.3EPSS 0.005