VYPR
Medium severity5.5NVD Advisory· Published Apr 1, 2026· Updated Apr 3, 2026

CVE-2025-66484

CVE-2025-66484

Description

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting, allowing arbitrary JavaScript execution and potential credential disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting, allowing arbitrary JavaScript execution and potential credential disclosure.

Vulnerability

Overview

IBM Aspera Shares versions 1 Shares versions 1.9.9 through 1.11.0 contain a stored cross-site scripting (XSS) vulnerability. The root cause is insufficient sanitization of user-supplied input, allowing attackers to embed arbitrary JavaScript code that is stored on the server and later executed in the context of the Web UI [1]. This is a classic stored XSS flaw (CWE-79).

Exploitation

An authenticated user with the ability to submit data (e.g., via file uploads, comments, or configuration fields) can inject malicious scripts. No special network position is required beyond standard web access. The attack does not require social engineering of the victim beyond viewing the affected page, as the script executes automatically when the stored content is rendered [1].

Impact

Successful exploitation allows the attacker to alter the intended functionality of the Web UI, potentially leading to disclosure of sensitive session credentials (e.g., session tokens or cookies) within a trusted session. This could enable account takeover or further lateral movement within the application [1].

Mitigation

IBM has addressed this vulnerability in Aspera Shares version 1.11.1. Users are strongly recommends upgrading to this version. No workarounds are documented; applying the security update is the only remediation [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IBM/Aspera Shares2 versions
    cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*range: >=1.9.9,<1.11.1
    • (no CPE)range: 1.9.9 through 1.11.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.