CVE-2025-66487Low· 2.7▾ SunlitIBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
aspera_shares >= 1.9.9, < 1.11.1Upgrade past the affected range:
aspera_shares 1.11.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66485Medium· 5.4IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers
CVE-2025-66486Medium· 4.8IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection
CVE-2025-13916Medium· 5.9IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
CVE-2025-66483Medium· 6.3IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
CVE-2025-66484Medium· 5.5IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting
CVE-2025-36122Medium· 6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocat…