QID 730739
Date Published: 2023-02-23
QID 730739: IBM Aspera Faspex Multiple Security Vulnerabilities (6952319)
Faspex is a centralized transfer solution that enables users to exchange files with each other using an email-like workflow.
Multiple Remote Code Execution (RCE), Cross-Site Scripting (XSS), Denial of Service (DoS) and other security vulnerabilities has been found in IBM Aspera Faspex.
Affected Versions:
IBM Aspera Faspex versions prior to 4.4.2 Patch Level 2
QID Detection Logic (Unauthenticated):
This QID sends a crafted payload (containg commands such as id or cat /etc/passwd) to aspera/faspex/package_relay/relay_package endpoint as a POST request and checks the response for code execution.
Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to execute arbitrary code on the target system.
Solution
Vendor has released updated versions to fix these vulnerabilities. Please refer IBM Aspera Faspex Security Advisory (6952319)
Vendor References
- 6952319 -
www.ibm.com/support/pages/node/6952319
CVEs related to QID 730739
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6952319 |
|