Known vulnerabilities in IBM Aspera Orchestrator

Software CPE: cpe:2.3:a:ibm_corporation:ibm_aspera_orchestrator:*:*:*:*:*:*:*:*
Total vulnerabilities: 42
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Aspera Orchestrator IBM Aspera Orchestrator is affected by 42 known vulnerabilities: 5 high, 25 medium, 12 low Critical High Medium Low

Vulnerabilities (42)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126644 - Improper Access Control
CVE-2026-41316
CWE-284 High
No
No
4.1.5 21.04.2026 SB2026042131
SB20260509132
SB2026051815
and 11 more
#VU95336 - Observable Response Discrepancy
CVE-2023-27281
CWE-204 Medium
No
No
4.0.1 PL2 05.08.2024 SB2024080527
#VU95334 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2023-27280
CWE-327 Medium
No
No
4.0.1 PL2 05.08.2024 SB2024080527
#VU95333 - Observable Response Discrepancy
CVE-2023-27283
CWE-204 Low
No
No
4.0.1 PL2 05.08.2024 SB2024080527
#VU95331 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-37407
CWE-78 High
No
No
- 05.08.2024 SB2024080514
#VU71773 - Incorrect Regular Expression
CVE-2020-27511
CWE-185 Low
No
No
4.0.1 PL2 02.02.2023 SB2021062151
SB2023020250
SB2024050725
and 1 more
#VU64083 - Out-of-bounds read
CVE-2022-28615
CWE-125 Low
No
No
4.0.1.2b9681 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 41 more
#VU60166 - Cryptographic Issues
CVE-2021-4160
CWE-310 Low
No
No
4.0.1.2b9681 28.01.2022 SB2022012811
SB2022031611
SB2022042517
and 29 more
#VU56681 - NULL Pointer Dereference
CVE-2021-34798
CWE-476 Medium
No
No
4.0.1.2b9681 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 44 more
#VU56680 - Out-of-bounds read
CVE-2021-36160
CWE-125 Medium
No
No
4.0.1.2b9681 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 22 more
#VU56064 - Out-of-bounds read
CVE-2021-3712
CWE-125 Medium
No
No
4.0.1.2b9681 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 142 more
#VU50745 - Improper input validation
CVE-2021-23840
CWE-20 Medium
No
No
4.0.1.2b9681 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 83 more
#VU50744 - Cryptographic Issues
CVE-2021-23839
CWE-310 Low
No
No
4.0.1.2b9681 17.02.2021 SB2021021702
SB2021041501
SB2021041502
and 15 more
#VU50740 - NULL Pointer Dereference
CVE-2021-23841
CWE-476 Medium
No
No
4.0.1.2b9681 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 66 more
#VU48896 - NULL Pointer Dereference
CVE-2020-1971
CWE-476 Medium
Available
No
4.0.1.2b9681 08.12.2020 SB2020120852
SB2020120903
SB2020120905
and 91 more
#VU21707 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-10735
CWE-79 Low
No
No
4.0.1 PL2 10.10.2019 SB2019010911
SB2019101009
SB2020093090
and 21 more
#VU17694 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8331
CWE-79 Low
No
No
4.0.1 PL2 14.02.2019 SB2019021412
SB2019031501
SB2019101009
and 28 more
#VU16956 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20676
CWE-79 Low
No
No
4.0.1 PL2 13.01.2019 SB2018121404
SB2019101009
SB2020093090
and 18 more
#VU16542 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20677
CWE-79 Low
No
No
4.0.1 PL2 14.12.2018 SB2018121404
SB2019101009
SB2020093090
and 18 more
#VU13901 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-14040
CWE-79 Low
No
No
4.0.1 PL2 17.07.2018 SB2018071803
SB2019031501
SB2020093090
and 24 more


Showing elements 1 - 20 out of 42