CNNVD-202601-3261 Information

CNNVD ID

CNNVD-202601-3261

CVE-2025-13925

  • CNNVD Published: 2026-01-20

Description (Chinese)

IBM Aspera Console是美国国际商业机器(IBM)公司的一个基于 Web 的应用程序。允许用户集中管理、监控和控制 Aspera 服务器(节点)和传输。 IBM Aspera Console 3.4.7版本存在日志信息泄露漏洞,该漏洞源于日志文件中存储潜在敏感信息,可能导致本地特权用户读取。

Description (English)

IBM Aspera Console is a Web-based application of IBM. Allows users to centrally manage, monitor and control the Aspera server (node) and transfer. Version 3.4.7 of IBM Aspera Console contains a log information leak that originates from the storage of potentially sensitive information in log files and may lead to local privileged users ’ access.

Hazard Level

High

Vulnerability Type

日志信息泄露

Affected Vendor

国际商业机器

Published

2026-01-20

Last Modified

2026-02-24

References

https://www.ibm.com/support/pages/node/7256544

Patch

https://www.ibm.com/products/aspera

Share on: