CVE-2022-47986: IBM Aspera Faspex Code Execution Vulnerability
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
Other sources
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera Faspexto a version that resolves this vulnerability.Fixed in 4.4.2 PL2
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47986?
The severity of CVE-2022-47986 is critical with a value of 9.8.
How does CVE-2022-47986 affect IBM Aspera Faspex?
CVE-2022-47986 affects IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier.
How can a remote attacker exploit CVE-2022-47986?
A remote attacker can exploit CVE-2022-47986 by sending a specially crafted obsolete API call.
What is the recommended action for CVE-2022-47986?
Refer to the appropriate IBM Security Bulletin for patch, upgrade, or suggested workaround information.
Where can I find more information about CVE-2022-47986?
More information about CVE-2022-47986 can be found in the IBM Security Bulletin and CVE Mitre.