Loading
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
Use CWE-502, Ibm vendor hub and Aspera Faspex product page to widen CVE-2022-47986 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-33137, CVE-2025-36040 and CVE-2025-36039 for nearby disclosures in the same product family.