IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Subscriptions

Vendors Products
Aspera Console Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

IBM strongly recommends that customers upgrade to the latest version of IBM Aspera Console:   Product(s)Fixing VRMPlatformLink to FixIBM Aspera Console3.4.8 FP1 Windows Link https://www.ibm.com/support/fixcentral/swg/doSelectFixes IBM Aspera Console3.4.8 FP1 Linux Link https://www.ibm.com/support/fixcentral/swg/doSelectFixes IBM Aspera Console3.4.8 FP1 Multiplatform Link https://www.ibm.com/support/fixcentral/swg/doSelectFixes


Workaround

No workaround given by the vendor.

History

Sat, 28 Feb 2026 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:aspera_console:*:*:*:*:*:*:*:*

Thu, 05 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 13:45:00 +0000

Type Values Removed Values Added
Description IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Title A SQL Injection vulnerability has been addressed in IBM Aspera Console
First Time appeared Ibm
Ibm aspera Console
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:aspera_console:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_console:3.4.8:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Console
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-26T15:04:18.212Z

Reserved: 2025-11-18T20:08:29.272Z

Link: CVE-2025-13379

cve-icon Vulnrichment

Updated: 2026-02-05T14:13:20.693Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-05T14:16:03.000

Modified: 2026-02-12T19:08:57.793

Link: CVE-2025-13379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses