IBM.Aspera.Faspex.CVE-2022-47986.Remote.Code.Execution
Description
This indicates an attack attempt against executing arbitrary code within the context of the target system.
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Affected Products
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier
Impact
System Compromise: Remote attackers can execute arbitrary code within the context of the target system
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
Version Updates
Date | Version | Detail |
---|---|---|
2023-05-18 | 1.00042 |