IBM-XFORCE-243512: Critical severity ibm aspera faspex on demand vulnerability
IBM Aspera Faspex code execution
Other sources
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
Affected Software
Event History
Frequently Asked Questions
What is the severity of IBM-XFORCE-243512?
The severity of IBM-XFORCE-243512 is critical.
How does IBM Aspera Faspex code execution vulnerability occur?
The IBM Aspera Faspex code execution vulnerability occurs due to a YAML deserialization flaw.
How can a remote attacker exploit the IBM Aspera Faspex code execution vulnerability?
A remote attacker can exploit the IBM Aspera Faspex code execution vulnerability by sending a specially crafted obsolete API call.
What is the affected software version of the IBM Aspera Faspex code execution vulnerability?
The affected software version of the IBM Aspera Faspex code execution vulnerability is 4.4.2 Patch Level 1 and earlier.
How can I fix the IBM Aspera Faspex code execution vulnerability?
To fix the IBM Aspera Faspex code execution vulnerability, refer to the appropriate IBM Security Bulletin for patch, upgrade, or suggested workaround information.