IBM Aspera Shares XML External Entity Injection Vulnerability

Vulnerability

A vulnerability allowing XML external entity injection (XXE) has been identified in IBM Aspera Shares versions 1.9.9 through 1.10.0 PL7. This vulnerability arises when the application processes XML data, creating an opportunity for remote authenticated attackers to exploit it. The exploitation of this vulnerability could lead to the exposure of sensitive information or the consumption of memory resources.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information or excessive memory usage, potentially leading to a denial-of-service condition.

Remediation

Users are advised to upgrade to IBM Aspera Shares version 1.10.0 PL8. Instructions for downloading this version are available on the IBM Support Fix Central website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.