IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7259448 |
|
History
Thu, 05 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Title | A SQL Injection vulnerability has been addressed in IBM Aspera Console | |
| First Time appeared |
Ibm
Ibm aspera Console |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:ibm:aspera_console:3.4.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_console:3.4.8:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Console |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-02-05T14:13:36.580Z
Reserved: 2025-11-18T20:08:29.272Z
Link: CVE-2025-13379
Updated: 2026-02-05T14:13:20.693Z
Status : Awaiting Analysis
Published: 2026-02-05T14:16:03.000
Modified: 2026-02-05T14:57:20.563
Link: CVE-2025-13379
No data.
OpenCVE Enrichment
No data.