CVE-2025-13459: IBM Aspera Console Denial of Service
Published Mar 12, 2026
·Updated
IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
Other sources
IBM Aspera Console could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.
— IBM
Affected Software
5 affected components
IBM Aspera Console>=3.3.0<=3.4.8
IBM Aspera Console<=3.3.0 - 3.4.8
All of the following
IBM Aspera Console>=3.3.0<3.4.9
Any of the following
Linux Linux kernel
Microsoft Windows
Remediation
Information
Remediation/Fixes It is strongly recommended that customers upgrade to the latest version of IBM Aspera Console: Product(s) Fixing VRM Platform Link to Fix IBM Aspera Console 3.4.9 Windows Link IBM Aspera Console 3.4.9 Linux Link
Event History
Mar 12, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Mar 13, 2026
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
RemedyDescriptionSeverityWeakness
Mar 16, 2026
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13459?
CVE-2025-13459 has a severity rating classified as medium due to its potential to cause denial of service.
2
How do I fix CVE-2025-13459?
To fix CVE-2025-13459, upgrade IBM Aspera Console to version 3.4.9 or later.
3
Who is affected by CVE-2025-13459?
IBM Aspera Console versions 3.3.0 through 3.4.8 are affected by CVE-2025-13459.
4
What kind of vulnerability is CVE-2025-13459?
CVE-2025-13459 is a Denial of Service vulnerability allowing a privileged user to disrupt service.
5
Can CVE-2025-13459 be exploited remotely?
CVE-2025-13459 can only be exploited by a privileged user who has local access to the IBM Aspera Console.