CVE-2024-38316

MEDIUM

IBM Aspera Shares <1.10.0 PL6 - DoS

Title source: llm
STIX 2.1

Description

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7182490

Scores

CVSS v3 4.3
EPSS 0.0010
EPSS Percentile 26.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
ibm/aspera_shares 1.10.0 (7 CPE variants)
ibm/aspera_shares 1.9.0 - 1.10.0
Published Feb 05, 2025
Tracked Since Feb 18, 2026