VulnSea

aspera_shares vulnerabilities

CVEs whose affected-version data names the aspera_shares package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2025-66487Low· 2.7
6mo ago

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

▾ Sunlitibm · aspera_sharesEPSS 0.33%via NVD
CVE-2025-66486Medium· 4.8
6mo ago

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

▾ Sunlitibm · aspera_sharesEPSS 0.24%via NVD
CVE-2025-66485Medium· 5.4
6mo ago

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including …

▾ Sunlitibm · aspera_sharesEPSS 0.20%via NVD
CVE-2025-66484Medium· 5.5
6mo ago

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent…

▾ Sunlitibm · aspera_sharesEPSS 0.19%via NVD
CVE-2025-66483Medium· 6.3
6mo ago

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

▾ Sunlitibm · aspera_sharesEPSS 0.18%via NVD
CVE-2025-13916Medium· 5.9
6mo ago

IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

▾ Sunlitibm · aspera_sharesEPSS 0.20%via NVD
aspera_shares vulnerabilities (CVEs) · VulnSea