CVE-2025-13379: A SQL Injection vulnerability has been addressed in IBM Aspera Console
IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Other sources
IBM Aspera Console is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13379?
CVE-2025-13379 is considered a critical vulnerability due to the potential for remote attackers to execute SQL injection attacks.
How do I fix CVE-2025-13379?
To fix CVE-2025-13379, upgrade IBM Aspera Console to a version later than 3.4.8.
What versions of IBM Aspera Console are affected by CVE-2025-13379?
IBM Aspera Console versions 3.4.0 to 3.4.8 are affected by CVE-2025-13379.
What impact does CVE-2025-13379 have on my data?
CVE-2025-13379 could allow attackers to view, add, modify, or delete sensitive information in the back-end database.
Who can exploit CVE-2025-13379?
CVE-2025-13379 can be exploited by any remote attacker with access to the affected IBM Aspera Console instance.