Description
Acunetix determined that the IBM Aspera Faspex is vulnerable to remote code execution due to insecure YAML deserialization. An attacker could exploit this vulnerability using specially-crafted serialized data to execute arbitrary code on the system or to perform a denial of service attack.
Remediation
Upgrade to the latest version of IBM Aspera Faspex
References
Security Bulletin: IBM Aspera Faspex 4.4.2 PL2 has addressed multiple vulnerabilities
Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails
Related Vulnerabilities
phpMyAdmin Improper Input Validation Vulnerability (CVE-2016-6630)
Oracle Database Server CVE-2010-0851 Vulnerability (CVE-2010-0851)
Caddy Web Server Improper Authentication Vulnerability (CVE-2018-21246)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7852)