First published: Fri Aug 23 2024(Updated: )
IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with privileged access to execute commands in a running Pod to elevate their user privileges.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect Enterprise | =5.0 | |
IBM App Connect Enterprise | =7.1 | |
IBM App Connect Enterprise | =7.2 | |
IBM App Connect Enterprise | =8.0 | |
IBM App Connect Enterprise | =8.1 | |
IBM App Connect Enterprise | =8.2 | |
IBM App Connect Enterprise | =9.0 | |
IBM App Connect Enterprise | =9.1 | |
IBM App Connect Enterprise | =9.2 | |
IBM App Connect Enterprise | =10.0 | |
IBM App Connect Enterprise | =10.1 | |
IBM App Connect Enterprise | =11.0 | |
IBM App Connect Enterprise | =11.1 | |
IBM App Connect Enterprise | =11.2 | |
IBM App Connect Enterprise | =11.3 | |
IBM App Connect Enterprise | =11.4 | |
IBM App Connect Enterprise | =11.5 | |
IBM App Connect Enterprise | =11.6 | |
IBM App Connect Enterprise | =12.0 | |
IBM App Connect Enterprise | =12.1 | |
IBM App Connect Enterprise | <=5.0-lts | |
IBM App Connect Enterprise | <=7.1 | |
IBM App Connect Enterprise | <=7.2 | |
IBM App Connect Enterprise | <=8.0 | |
IBM App Connect Enterprise | <=8.1 | |
IBM App Connect Enterprise | <=8.2 | |
IBM App Connect Enterprise | <=9.0 | |
IBM App Connect Enterprise | <=9.1 | |
IBM App Connect Enterprise | <=9.2 | |
IBM App Connect Enterprise | <=10.0 | |
IBM App Connect Enterprise | <=10.1 | |
IBM App Connect Enterprise | <=11.0 | |
IBM App Connect Enterprise | <=11.1 | |
IBM App Connect Enterprise | <=11.2 | |
IBM App Connect Enterprise | <=11.3 | |
IBM App Connect Enterprise | <=11.4 | |
IBM App Connect Enterprise | <=11.5 | |
IBM App Connect Enterprise | <=11.6 | |
IBM App Connect Enterprise | <=12.0-lts | |
IBM App Connect Enterprise | <=12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43915 is considered a high-severity vulnerability due to its potential for abuse by users with privileged access.
To fix CVE-2022-43915, it is recommended to apply the latest security patches provided by IBM for the affected versions of App Connect Enterprise Certified Container.
CVE-2022-43915 affects multiple versions of IBM App Connect Enterprise Certified Container, including 5.0 through 12.1.
Exploiting CVE-2022-43915 requires privileged access to execute commands in running Pods.
There are currently no specific workarounds for CVE-2022-43915 recommended outside of applying updates from IBM.