Security Advisory

CVE-2025-0162

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-07 16:38:40
Last updated 2025-09-01 01:08:29
Assigner ibm
State PUBLISHED

Description

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.