Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Aspera Faspex | 4.4.2 Patch Level 1 and earlier | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Aspera Faspex Pre Auth RCE | https://github.com/ohnonoyesyes/CVE-2022-47986 | POC Details |
| 2 | None | https://github.com/dhina016/CVE-2022-47986 | POC Details |
| 3 | CVE-2022-47986: Python, Ruby, NMAP and Metasploit modules to exploit the vulnerability. | https://github.com/mauricelambert/CVE-2022-47986 | POC Details |
| 4 | IBM Aspera Faspex through 4.4.2 Patch Level 1 is susceptible to remote code execution via a YAML deserialization flaw. This can allow an attacker to send a specially crafted obsolete API call and thereby execute arbitrary code, obtain sensitive data, and/or execute other unauthorized operations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-47986.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-24960 | 7.5 HIGH | IBM InfoSphere Information Server information disclosure |
| CVE-2022-36775 | 6.5 MEDIUM | IBM Security Verify Access HOST header injection |
| CVE-2022-40232 | 6.3 MEDIUM | IBM Sterling B2B Integrator Standard Edition improper access control |
| CVE-2023-24964 | 6.2 MEDIUM | IBM InfoSphere Information Server information disclosure |
| CVE-2022-43930 | 6.2 MEDIUM | IBM Db2 for Linux, UNIX and Windows information disclosure |
| CVE-2022-43927 | 5.9 MEDIUM | IBM Db2 for Linux, UNIX and Windows information disclosure |
| CVE-2022-34351 | 5.9 MEDIUM | IBM QRadar SIEM information disclosure |
| CVE-2023-22868 | 5.4 MEDIUM | IBM Aspera Faspex cross-site scripting |
| CVE-2022-41734 | 5.3 MEDIUM | IBM Maximo Asset Management information disclosure |
| CVE-2022-43929 | 4.9 MEDIUM | IBM Db2 for Linux, UNIX and Windows denial of service |
| CVE-2022-43579 | 4.6 MEDIUM | IBM Sterling B2B Integrator Standard Edition cross-site scripting |
| CVE-2022-40231 | 4.3 MEDIUM | IBM Sterling B2B Integrator Standard Edition improper access control |
No comments yet