Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/ibm/aspera-shares

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

IBM Aspera Shares versions 1.9.9 through 1.11.0 have a vulnerability where the software does not properly rate limit the frequency of emails sent by authenticated users. This flaw could allow an authenticated user to send emails excessively, potentially causing email flooding or a denial of service condition. The vulnerability is identified as CWE-770, related to allocation of resources without limits or throttling. The CVSS score is 2.7, indicating a low severity impact. There is no indication of known exploits in the wild.

Join the discussion

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

Join the discussion

IBM Aspera Shares versions 1.9.9 through 1.11.0 contain a vulnerability due to improper validation of HOST headers, leading to HTTP header injection. This flaw can enable attackers to perform attacks such as cross-site scripting, cache poisoning, or session hijacking. The vulnerability has a medium severity with a CVSS score of 5.4. No official patch or vendor advisory is provided in the input data, and no known exploits are reported in the wild.

Join the discussion
0

IBM Aspera Shares versions 1.9.9 through 1.11.0 contain a stored cross-site scripting (XSS) vulnerability. This flaw allows an attacker to embed arbitrary JavaScript code in the web user interface, which can alter intended functionality and potentially lead to the disclosure of credentials within a trusted session. The vulnerability has a medium severity rating with a CVSS score of 5.5. There is no information about an available patch or official remediation from IBM at this time. No known exploits are reported in the wild.

Join the discussion

IBM Aspera Shares versions 1.9.9 through 1.11.0 contain a vulnerability where sessions are not invalidated after a password reset. This insufficient session expiration could allow an authenticated user to impersonate another user on the system. The vulnerability is identified as CWE-613 and has a CVSS 3.1 base score of 6.3, indicating a medium severity level. No official patch or remediation information is provided in the available data.

Join the discussion

IBM Aspera Shares versions 1.9.9 through 1.11.0 use cryptographic algorithms that are weaker than expected, potentially allowing attackers to decrypt highly sensitive information. The vulnerability is identified as CWE-327, indicating the use of broken or risky cryptography. The CVSS score is 5.9, reflecting a medium severity level. There is no indication of known exploits in the wild. No official patch or remediation information is provided in the available data.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/ibm/aspera-shares
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses