{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-13219","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-11-14T20:37:15.537Z","datePublished":"2026-03-10T20:08:20.129Z","dateUpdated":"2026-03-11T14:09:47.903Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-03-10T20:10:12.623Z"},"title":"Multiple vulnerabilities in IBM Aspera Orchestrator","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-598","description":"CWE-598 Use of GET Request Method With Sensitive Query Strings","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Aspera Orchestrator","versions":[{"status":"affected","version":"3.0.0","lessThanOrEqual":"4.1.2","versionType":"semver"}],"cpes":["cpe:2.3:a:ibm:aspera_orchestrator:3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:aspera_orchestrator:4.1.2:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7263083","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":5.9,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}}],"solutions":[{"lang":"en","value":"ProductVersionPlatformLink to FixIBM Aspera Orchestrator4.1.3Linux Link https://www.ibm.com/support/fixcentral/swg/selectFixes","supportingMedia":[{"type":"text/html","base64":false,"value":"<div><table><tbody><tr><td><strong>Product</strong></td><td><strong>Version</strong></td><td><strong>Platform</strong></td><td><strong>Link to Fix</strong></td></tr><tr><td>IBM Aspera Orchestrator</td><td>4.1.3</td><td>Linux</td><td><a href=\"https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EOther%20software&amp;product=ibm/Other+software/IBM+Aspera+Orchestrator&amp;release=4.1.3&amp;platform=Linux&amp;function=all\" rel=\"nofollow\">Link</a></td></tr></tbody></table></div><p><br></p>"}]}],"x_generator":{"engine":"ibm-cvegen"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-03-11T14:09:40.385415Z","id":"CVE-2025-13219","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-03-11T14:09:47.903Z"}}]}}