CVE-2025-0162: IBM Aspera Shares XML external entity injection
IBM Aspera is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0162?
CVE-2025-0162 has a moderate severity level, as it could lead to information exposure and memory resource consumption.
How do I fix CVE-2025-0162?
To fix CVE-2025-0162, upgrade IBM Aspera Shares to the latest version beyond 1.10.0 PL7.
Who is affected by CVE-2025-0162?
CVE-2025-0162 affects IBM Aspera Shares versions from 1.9.9 to 1.10.0 PL7.
What type of attack is CVE-2025-0162 exploiting?
CVE-2025-0162 exploits an XML external entity injection (XXE) vulnerability.
What could an attacker achieve by exploiting CVE-2025-0162?
An attacker exploiting CVE-2025-0162 could expose sensitive information or consume system memory resources.