IBM Product Security Update Advisory (CVE-2025-0162)

Overview

We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-0162

IBM Aspera Shares Versions: 1.9.9 through 1.10.0 PL7

 

 

Resolved Vulnerabilities

XML External Entity Injection Vulnerability (CVE-2025-0162)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
 

 

CVE-2025-0162

IBM Aspera Shares Version: 1.10.0 PL8

 

 

References

[1] Security Bulletin: IBM Aspera Shares is vulnerable to bypass security restrictions and an external entity injection (CVE-2024-45409, CVE-2025-0162)
https://www.ibm.com/support/pages/node/7185096