Vulnerabilities
Vulnerable Software
Ibm:  >> Aspera Faspex  >> 4.4.2  Security Vulnerabilities
IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654.
CVSS Score
6.5
EPSS Score
0.0
Published
2023-03-21
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.
CVSS Score
9.9
EPSS Score
0.001
Published
2023-03-21
CVE-2022-47986
Known exploited
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
CVSS Score
9.8
EPSS Score
0.943
Published
2023-02-17


Contact Us

Shodan ® - All rights reserved