Umbra Wiki cve cve/CVE-2022-47986
Back to wiki

CVE-2022-47986 — IBM Aspera Faspex Code Execution Vulnerability

provenance: imported · CVE: CVE-2022-47986

CVE-2022-47986: IBM Aspera Faspex Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project IBM
Product Aspera Faspex
Date added 2023-02-21
Due date 2023-03-14
Ransomware campaign use Known

Description

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://exchange.xforce.ibmcloud.com/vulnerabilities/243512?_ga=2.189195179.1800390251.1676559338-700333034.1676325890; https://nvd.nist.gov/vuln/detail/CVE-2022-47986

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-47986
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog