PatchSiren cyber security CVE debrief
CVE-2025-66487 IBM CVE debrief
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. This vulnerability allows an authenticated user to send emails at an unlimited frequency, potentially leading to email flooding or denial of service. Defenders and administrators responsible for IBM Aspera Shares installations should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts.
- Vendor
- IBM
- Product
- Aspera Shares
- CVSS
- LOW 2.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-01
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-04-01
- Advisory updated
- 2026-09-30
Who should care
Defenders and administrators responsible for IBM Aspera Shares installations, especially in environments where email flooding or denial of service could have significant impacts.
Why it matters
Defenders should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts. The vulnerability allows an authenticated user to send emails at an unlimited frequency, potentially leading to email flooding or denial of service.
- Potential email flooding or denial of service could impact email services and user productivity.
- Verify and apply the vendor's patch for IBM Aspera Shares versions 1.9.9 through 1.11.0 to prevent exploitation.
Technical summary
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. The vulnerability allows an authenticated user to send emails at an unlimited frequency, potentially leading to email flooding or denial of service. Defenders should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts.
Recommended defensive actions
- Verify and apply the vendor's patch for IBM Aspera Shares versions 1.9.9 through 1.11.0.
- Implement rate limiting on email sending functionality to prevent email flooding or denial of service.
- Monitor email sending activity for potential abuse or anomalies.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. The vulnerability is confirmed in IBM Aspera Shares versions 1.9.9 through 1.11.0. Defenders should verify the affected scope and apply the vendor's patch to prevent exploitation. The CVE Program and NVD provide official records and assessments of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66487 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66487
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66487 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66487
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7267848
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.