Description
IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Published: 2026-04-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

IBM Aspera Shares versions 1.9.9 to 1.11.0 use cryptographic algorithms that are weaker than expected, allowing an attacker to decrypt data that is supposed to remain confidential. The weakness is reflected by the CWE‑327 identifier, which describes the inappropriate use of cryptographic primitives that have known vulnerabilities. As a result, confidential information transmitted or stored by the software could be exposed without authorization. The description makes no mention of a specific algorithm, but the impact is clearly the potential loss of confidentiality.

Affected Systems

The affected product is IBM Aspera Shares on both Windows and Linux operating systems. Impacted releases are 1.9.9, 1.10.x, and 1.11.0. The 1.11.1 release resolves the issue for both platforms, with update packages available through IBM’s Fix Central for Windows and Linux. No other vendors or products are reported to be affected by this cryptographic weakness.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity vulnerability. The EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been documented. The likely attack vector would require an attacker who can access data encrypted by Aspera Shares or intercept that data in transit; however, no publicly available exploit technique is described in the advisory. The principal risk remains to the confidentiality of data, and it is mitigated once the software is updated to a version that uses robust cryptographic algorithms.

Generated by OpenCVE AI on April 6, 2026 at 21:52 UTC.

Remediation

Vendor Solution

Product(s)Fixing VRMPlatformLink to FixIBM Aspera Shares1.11.1 Windows click here https://www.ibm.com/support/fixcentral/swg/selectFixes IBM Aspera Shares1.11.1 Linux click here https://www.ibm.com/support/fixcentral/swg/selectFixes


OpenCVE Recommended Actions

  • Update IBM Aspera Shares to version 1.11.1 using the IBM Fix Central links provided for Windows and Linux.

Generated by OpenCVE AI on April 6, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:aspera_shares:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 02 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
Title Multiple vulnerabilities have been addressed in IBM Aspera Shares
First Time appeared Ibm
Ibm aspera Shares
Weaknesses CWE-327
CPEs cpe:2.3:a:ibm:aspera_shares:1.11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_shares:1.9.9:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Shares
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Aspera Shares
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-04-02T14:00:16.600Z

Reserved: 2025-12-02T18:42:50.665Z

Link: CVE-2025-13916

cve-icon Vulnrichment

Updated: 2026-04-02T14:00:06.628Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-01T21:16:56.803

Modified: 2026-04-06T16:49:10.043

Link: CVE-2025-13916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-07T08:07:26Z

Weaknesses