CVE-2025-66487: IBM Aspera Shares

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

Affected products

  • IBM Aspera Shares: from 1.9.9, before 1.11.1 (fixed in 1.11.1)

Published 2026-04-01. Last modified 2026-10-07.