Skip to main content

Vendor/product archive

ibm / aspera_shares CVEs

Beta · best-effort

17 CVEs tagged to ibm / aspera_shares0 Critical, 1 High, 15 Medium, 1 Low, 0 Unrated.

CVE-2025-66487

Published Apr 1, 2026

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of s…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-66486

Published Apr 1, 2026

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's We…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66485

Published Apr 1, 2026

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66484

Published Apr 1, 2026

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66483

Published Apr 1, 2026

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0162

Published Mar 7, 2025

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit t…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-56473

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56472

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the W…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56471

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the sy…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56470

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the sy…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38318

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim'…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38317

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thu…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38316

Published Feb 5, 2025

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38315

Published Sep 16, 2024

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38018

Published Aug 12, 2024

IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4731

Published Sep 21, 2020

IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1