CVE-2022-47986
Description
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
Summary dbcve.org
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier contains a YAML deserialization vulnerability in an obsolete API call. Remote attackers can exploit this flaw to execute arbitrary code on the affected system without authentication, achieving complete system compromise.
Mitigation
Upgrade to IBM Aspera Faspex 4.4.2 Patch Level 2 or later, which removes the vulnerable obsolete API call. If patching is delayed, restrict network access to the Faspex interface and implement additional authentication controls.