IBM.Aspera.Faspex.CVE-2022-47986.Remote.Code.Execution

description-logoDescription

This indicates an attack attempt against executing arbitrary code within the context of the target system.
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system.

affected-products-logoAffected Products

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary code within the context of the target system

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.

Version Updates

Date Version Detail
2023-05-18 1.00042

CVE References

CVE-2022-47986