CVE-2025-13460

MEDIUM

IBM Aspera Console Information Disclosure

Title source: cna
STIX 2.1

Description

IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 11.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-204
Status published
Products (2)
IBM/Aspera Console 3.3.0 - 3.4.8
ibm/aspera_console 3.3.0 - 3.4.9
Published Mar 16, 2026
Tracked Since Mar 16, 2026