← Vulnerability feed

Vulnerability record · CVE-2022-47986 · published 17 February 2023

CVE-2022-47986: IBM Aspera Faspex YAML Deserialization Remote Code Execution

Ibm · Aspera Faspex

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier contain a YAML deserialization flaw (CWE-502) reachable through an obsolete API call. A remote, unauthenticated attacker can send a crafted request to execute arbitrary code on the server. The vulnerable API call was removed in Faspex 4.4.2 PL2, so the fix is a version upgrade.

9.8 CVSS 3.1 Critical CISA KEV since 21 Feb 2023 Known ransomware use EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, KEV listing, documented ransomware use, and near-maximum EPSS probability.

What it is

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier contain a YAML deserialization flaw (CWE-502) reachable through an obsolete API call. A remote, unauthenticated attacker can send a crafted request to execute arbitrary code on the server. The vulnerable API call was removed in Faspex 4.4.2 PL2, so the fix is a version upgrade.

Impact

Successful exploitation gives the attacker arbitrary code execution on the Faspex server, typically with the privileges of the Faspex service. That enables data theft, lateral movement into the file-transfer environment, and full host compromise.

Attack surface

Reachable over the network via the Faspex HTTP(S) interface using the obsolete API endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

CISA added it to KEV on 2023-02-21 with a 2023-03-14 remediation due date and flags known ransomware campaign use; EPSS is 0.99968 (99.976th percentile), and public exploit material is referenced via Packet Storm.

What to do

  • Upgrade IBM Aspera Faspex to 4.4.2 Patch Level 2 or later, which removes the obsolete API call.
  • If immediate upgrade is not possible, block or restrict network access to the Faspex web/API interface to trusted sources only.
  • Treat any internet-exposed Faspex instance as compromised until triaged, given KEV listing and ransomware use.
  • Monitor IBM's advisory page (node/6952319) for updated guidance and interim fixes.

Detection

  • Inspect Faspex HTTP access logs for requests to obsolete or unexpected API endpoints, especially POSTs with YAML-formatted bodies.
  • Hunt for unexpected child processes spawned by the Faspex service (Java/web container) on the host.
  • Review outbound network connections from the Faspex server for signs of post-exploitation or ransomware staging.
  • Correlate host and network telemetry around the KEV due date window for anomalous activity on Faspex systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-47986 to the Known Exploited Vulnerabilities catalog on 21 February 2023 as "IBM Aspera Faspex Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 March 2023.

Ransomware crews whose documented playbooks reference this CVE: