PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66487 IBM CVE debrief

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. This vulnerability allows an authenticated user to send emails at an unlimited frequency, potentially leading to email flooding or denial of service. Defenders and administrators responsible for IBM Aspera Shares installations should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts.

Vendor
IBM
Product
Aspera Shares
CVSS
LOW 2.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-01
Original CVE updated
2026-09-30
Advisory published
2026-04-01
Advisory updated
2026-09-30

Who should care

Defenders and administrators responsible for IBM Aspera Shares installations, especially in environments where email flooding or denial of service could have significant impacts.

Why it matters

Defenders should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts. The vulnerability allows an authenticated user to send emails at an unlimited frequency, potentially leading to email flooding or denial of service.

  • Potential email flooding or denial of service could impact email services and user productivity.
  • Verify and apply the vendor's patch for IBM Aspera Shares versions 1.9.9 through 1.11.0 to prevent exploitation.

Technical summary

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. The vulnerability allows an authenticated user to send emails at an unlimited frequency, potentially leading to email flooding or denial of service. Defenders should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially in environments where email flooding or denial of service could have significant impacts.

Recommended defensive actions

  • Verify and apply the vendor's patch for IBM Aspera Shares versions 1.9.9 through 1.11.0.
  • Implement rate limiting on email sending functionality to prevent email flooding or denial of service.
  • Monitor email sending activity for potential abuse or anomalies.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. The vulnerability is confirmed in IBM Aspera Shares versions 1.9.9 through 1.11.0. Defenders should verify the affected scope and apply the vendor's patch to prevent exploitation. The CVE Program and NVD provide official records and assessments of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66487 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66487

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66487 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66487

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.