CVE-2024-38316: IBM Aspera Shares
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
Affected products
- IBM Aspera Shares: from 1.9.0, before 1.10.0 (fixed in 1.10.0); version 1.10.0 only
Published 2025-02-05. Last modified 2026-06-17.