PT-2023-1609 · Ibm · Ibm Aspera Faspex
CVE-2022-47986
·
Publicado
2023-02-03
·
Atualizado
2025-10-27
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Aspera Faspex versions 4.4.2 Patch Level 1 and earlier
Description
The issue is related to a YAML deserialization flaw, allowing a remote attacker to execute arbitrary code on the system by sending a specially crafted obsolete API call. The obsolete API call was removed in Faspex 4.4.2 PL2. This flaw can be exploited to execute arbitrary code on the system.
Recommendations
For IBM Aspera Faspex versions 4.4.2 Patch Level 1 and earlier, update to Faspex 4.4.2 Patch Level 2 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable
/package relay/relay package API endpoint until a patch is available.Exploit
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Aspera Faspex