CVE-2022-47986 - IBM Aspera Faspex Code Execution Vulnerability
Project:IBM
Product:Aspera Faspex
Date Added:2023-02-21Due Date:2023-03-14
Vulnerability Name
IBM Aspera Faspex Code Execution Vulnerability
Description
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply updates per vendor instructions.
Additional Notes
https://exchange.xforce.ibmcloud.com/vulnerabilities/243512?_ga=2.189195179.1800390251.1676559338-700333034.1676325890
https://nvd.nist.gov/vuln/detail/CVE-2022-47986