Executive brief
IBM Aspera Faspex 5, a high-speed file transfer and collaboration platform, is vulnerable to a security flaw that allows an authorized user to take control of the server. By exploiting this vulnerability, an attacker with high-level credentials can run unauthorized commands, potentially leading to full system compromise, data theft, or disruption of file transfer services. Organizations should update to version 5.0.16 or later to mitigate this risk.
Technical details
IBM Aspera Faspex 5 is vulnerable to an OS command injection (CWE-78) within its web interface. A remote authenticated attacker with high privileges (PR:H) can exploit this vulnerability by sending specially crafted input to the application, which is then improperly neutralized before being passed to a system shell. Successful exploitation allows the attacker to execute arbitrary commands on the underlying operating system with the privileges of the application process. This vulnerability is addressed in IBM Aspera Faspex version 5.0.16.
Affected products
- IBM Aspera Faspex 5 5.0.0 through 5.0.15.4
Timeline
- 2026-07-28: advisory: IBM published the security bulletin and NVD record.
- 2026-07-28: patched: Vulnerability addressed in version 5.0.16.