
CVE-2025-66483 IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the s… https://www.cve.org/CVERecord?id=CVE-2025-66483
Post summary
The tweet announces a session persistence flaw in IBM Aspera Shares that could permit authenticated users to impersonate others after resetting passwords.
