CVE-2025-0162

Publication date

2025-03-07 16:38:40

Family

ibm

State

PUBLISHED

Description

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.