IBM Aspera Faspex Code Execution Vulnerability
IBM — Aspera Faspex
- Added to KEV catalog
- 21 February 2023
- Federal remediation due date
- 14 March 2023
- Weakness classification (CWE)
- CWE-502
CISA Description
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
Required action
Apply updates per vendor instructions.
Notes
https://exchange.xforce.ibmcloud.com/vulnerabilities/243512?_ga=2.189195179.1800390251.1676559338-700333034.1676325890; https://nvd.nist.gov/vuln/detail/CVE-2022-47986
More IBM Vulnerabilities
IBM Langflow Code Injection Vulnerability
IBM InfoSphere BigInsights Invalid Input Vulnerability
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
IBM Data Risk Manager Directory Traversal Vulnerability
IBM Data Risk Manager Remote Code Execution Vulnerability
Is this vulnerability present in your environment?
CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.
Explore VAPT Services