CVE-2022-43915: IBM App Connect Enterprise Certified Container
IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with privileged access to execute commands in a running Pod to elevate their user privileges.
Other sources
IBM App Connect Enterprise Certified Container does not limit calls to unshare in running Pods. This can allow a user with access to execute commands in a running Pod to elevate their user privileges.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43915?
CVE-2022-43915 is considered a high-severity vulnerability due to its potential for abuse by users with privileged access.
How do I fix CVE-2022-43915?
To fix CVE-2022-43915, it is recommended to apply the latest security patches provided by IBM for the affected versions of App Connect Enterprise Certified Container.
Which versions are affected by CVE-2022-43915?
CVE-2022-43915 affects multiple versions of IBM App Connect Enterprise Certified Container, including 5.0 through 12.1.
What kind of access does CVE-2022-43915 require to exploit?
Exploiting CVE-2022-43915 requires privileged access to execute commands in running Pods.
Is there any known workaround for CVE-2022-43915?
There are currently no specific workarounds for CVE-2022-43915 recommended outside of applying updates from IBM.