IBM Product Security Update Advisory (CVE-2025-0162)
Overview
We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-0162
IBM Aspera Shares Versions: 1.9.9 through 1.10.0 PL7
Resolved Vulnerabilities
XML External Entity Injection Vulnerability (CVE-2025-0162)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-0162
IBM Aspera Shares Version: 1.10.0 PL8
References
[1] Security Bulletin: IBM Aspera Shares is vulnerable to bypass security restrictions and an external entity injection (CVE-2024-45409, CVE-2025-0162)
https://www.ibm.com/support/pages/node/7185096