CRITICAL

CVE-2022-47986

Ibm Aspera Faspex 2023-02-17 CVSS v3.1
CVSS
9.8
KEV

Description

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.

Summary dbcve.org

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier contains a YAML deserialization vulnerability in an obsolete API call. Remote attackers can exploit this flaw to execute arbitrary code on the affected system without authentication, achieving complete system compromise.

Mitigation

Upgrade to IBM Aspera Faspex 4.4.2 Patch Level 2 or later, which removes the vulnerable obsolete API call. If patching is delayed, restrict network access to the Faspex interface and implement additional authentication controls.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

99.97%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE