CVE-2024-56473: IBM Aspera Shares

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.

Affected products

  • IBM Aspera Shares: from 1.9.0, before 1.10.0 (fixed in 1.10.0); version 1.10.0 only

Published 2025-02-05. Last modified 2026-06-17.