Skip to content
COOEY

EXPOSURES › CVE-2022-47986

CVE-2022-47986

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-02-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-47986 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

A YAML deserialization flaw in IBM Aspera Faspex allowed remote attackers to execute code, leading to ransomware-linked incidents.

IBM Aspera Faspex suffered a critical YAML deserialization vulnerability (CVE-2022-47986) that enabled remote code execution. This failure is highly relevant to DIB organizations because it was actively exploited in the wild and linked to ransomware attacks, demonstrating that unpatched or poorly secured data transfer tools can become ransomware entry points. Organizations must ensure their data transfer and file-sharing solutions are patched and monitored for exploitation.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a severe failure in patch management and threat detection that directly impacted operational security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

AFFECTED FEDRAMP PRODUCTS · 5
PRODUCTSTATUS
IBM Cloud for Government
IBM
Authorized
IBM Federal HR Cloud
IBM
Authorized
IBM Maximo and TRIRIGA on Cloud for U.S. Federal
IBM
Authorized
MaaS360 Enterprise Mobility Management
IBM
Authorized
SmartCloud for Government
IBM
Authorized