CVE-2022-47986

NVD Published Date: February 17, 2023 at 04:15 PM
NVD Last Modified: April 26, 2023 at 08:01 PM
Download Patch
Vulnerability ID
CVE-2022-47986
Severity
CRITICAL
Severity Score
9.8
Summary
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE ID
CWE-502

Recent Publish

CVE-2023-23397

CVE-2024-7903

CVE-2024-7904

CVE-2024-7905

CVE-2024-43353

Microsoft Dynamics 365 Server, v9.1 (on-premises) Update 1.28

See SecOps Solution
in action

Schedule Demo