Junglewise Threat Intelligence

CVE-2022-47986: IBM Aspera Faspex Code Execution Vulnerability

CVE-2022-47986 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-02-21

Technologies: IBM Aspera Faspex. Vendors: IBM.

Executive brief

IBM Aspera Faspex is vulnerable to remote code execution due to a YAML deserialization flaw in an obsolete API call. An unauthenticated attacker can exploit this by sending a specially crafted API request to execute arbitrary commands on the system.

Affected products

  • IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier

Timeline

  • 2023-02-21: disclosed
  • 2023-02-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-21: advisory
  • 2023-02-21: exploited: Reported as exploited in the wild per CISA KEV entry.

Related threats