CVE-2024-38316

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
References
Link Resource
https://www.ibm.com/support/pages/node/7182490 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level4:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level5:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level6:*:*:*:*:*:*

History

06 Mar 2025, 20:57

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7182490 - () https://www.ibm.com/support/pages/node/7182490 - Vendor Advisory
First Time Ibm aspera Shares
Ibm
CPE cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level6:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level2:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level4:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level1:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level5:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.10.0:patch_level3:*:*:*:*:*:*

22 Feb 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) IBM Aspera Shares 1.9.0 a 1.10.0 PL6 no limita adecuadamente la frecuencia que un usuario autenticado puede enviar correos electrónicos, lo que podría dar lugar a inundaciones por correo electrónico o una negación de servicio.
Summary (en) IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. (en) IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

05 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 23:15

Updated : 2025-03-06 20:57


NVD link : CVE-2024-38316

Mitre link : CVE-2024-38316

CVE.ORG link : CVE-2024-38316


JSON object : View

Products Affected

ibm

  • aspera_shares
CWE
CWE-770

Allocation of Resources Without Limits or Throttling