IBM Aspera Orchestrator
cpe:2.3:a:ibm:aspera_orchestrator:*:*:*:*:*:*:*
- >= 4.0.0, <= 4.1.0
A vulnerability exists in IBM Aspera Orchestrator versions 4.0.0 to 4.1.0, allowing an authenticated user to change another user's password without knowing the original password. This issue arises from unverified password change mechanisms, potentially leading to unauthorized access.
Exploitation of this vulnerability could result in unauthorized password changes, allowing users to gain access to accounts they do not own.
Users are advised to upgrade to IBM Aspera Orchestrator version 4.1.1. Instructions for downloading this version are available on the IBM Support Fix Central website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.