QID 730739

Date Published: 2023-02-23

QID 730739: IBM Aspera Faspex Multiple Security Vulnerabilities (6952319)

Faspex is a centralized transfer solution that enables users to exchange files with each other using an email-like workflow.

Multiple Remote Code Execution (RCE), Cross-Site Scripting (XSS), Denial of Service (DoS) and other security vulnerabilities has been found in IBM Aspera Faspex.

Affected Versions: IBM Aspera Faspex versions prior to 4.4.2 Patch Level 2
QID Detection Logic (Unauthenticated):
This QID sends a crafted payload (containg commands such as id or cat /etc/passwd) to aspera/faspex/package_relay/relay_package endpoint as a POST request and checks the response for code execution.

Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Vendor has released updated versions to fix these vulnerabilities. Please refer IBM Aspera Faspex Security Advisory (6952319)
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    6952319 URL Logo www.ibm.com/support/pages/node/6952319