Home/Product/ibm aspera shares
Product

ibm aspera shares

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-66487
>= 1.9.9 and < 1.11.1
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, whic
2.7LOW
CVE-2025-66486
>= 1.9.9 and < 1.11.1
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which
4.8MEDIUM
CVE-2025-66485
>= 1.9.9 and < 1.11.1
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST
5.4MEDIUM
CVE-2025-66484
>= 1.9.9 and < 1.11.1
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbi
5.5MEDIUM
CVE-2025-66483
>= 1.9.9 and <= 1.11.0
IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user
6.3MEDIUM
CVE-2025-13916
>= 1.9.9 and < 1.11.1
IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt
5.9MEDIUM
CVE-2025-0162
>= 1.9.9 and < 1.10.0
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data
7.1HIGH
CVE-2024-56473
>= 1.9.0 and < 1.10.0
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due
5.3MEDIUM
CVE-2024-56472
>= 1.9.0 and < 1.10.0
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated
6.4MEDIUM
CVE-2024-56471
>= 1.9.0 and < 1.10.0
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated
5.4MEDIUM
CVE-2024-56470
>= 1.9.0 and < 1.10.0
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated
5.4MEDIUM
CVE-2024-38318
>= 1.9.0 and < 1.10.0
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, w
4.8MEDIUM
CVE-2024-38317
>= 1.9.0 and < 1.10.0
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to
4.8MEDIUM
CVE-2024-38316
>= 1.9.0 and < 1.10.0
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails,
4.3MEDIUM
CVE-2024-38315
>= 1.0.0 and < 1.10.0
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated use
6.3MEDIUM
CVE-2023-38018
all versions
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impers
6.3MEDIUM
CVE-2020-4731
<= 1.9.14
IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja
6.1MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin