CVE-2025-13460: IBM Aspera Console Information Disclosure
Published Mar 12, 2026
·Updated
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.
Other sources
IBM Aspera Console could allow an attacker to enumerate usernames due to an observable response discrepancy.
— IBM
Affected Software
5 affected components
IBM Aspera Console>=3.3.0<=3.4.8
IBM Aspera Console<=3.3.0 - 3.4.8
All of the following
IBM Aspera Console>=3.3.0<3.4.9
Any of the following
Linux Linux kernel
Microsoft Windows
Remediation
Information
Remediation/Fixes It is strongly recommended that customers upgrade to the latest version of IBM Aspera Console: Product(s) Fixing VRM Platform Link to Fix IBM Aspera Console 3.4.9 Windows Link IBM Aspera Console 3.4.9 Linux Link
Event History
Mar 12, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Mar 13, 2026
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
RemedyDescriptionSeverityWeakness
Mar 16, 2026
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13460?
CVE-2025-13460 has a moderate severity rating due to the potential for username enumeration.
2
How do I fix CVE-2025-13460?
To mitigate CVE-2025-13460, upgrade IBM Aspera Console to a version later than 3.4.8.
3
What versions are affected by CVE-2025-13460?
CVE-2025-13460 affects IBM Aspera Console versions 3.3.0 through 3.4.8.
4
What type of vulnerability is CVE-2025-13460?
CVE-2025-13460 is an information disclosure vulnerability allowing username enumeration.
5
Can CVE-2025-13460 lead to further attacks?
Yes, if exploited, CVE-2025-13460 could facilitate unauthorized access to accounts.