IBM.Aspera.Faspex.CVE-2022-47986.Remote.Code.Execution

description-logoDescription

This indicates an attack attempt against executing arbitrary code within the context of the target system.
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system.

description-logoOutbreak Alert

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system.

View the full Outbreak Alert Report

affected-products-logoAffected Products

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary code within the context of the target system

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.

Version Updates

Date Version Detail
2023-03-03 0.00343

CVE References

CVE-2022-47986