PT-2024-11667 · Ibm · Ibm App Connect Enterprise Certified Container

Published

2024-08-24

·

Updated

2024-09-21

·

CVE-2022-43915

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM App Connect Enterprise Certified Container versions 5.0 through 12.1
Description The issue allows a user with privileged access to execute commands in a running Pod, potentially elevating their user privileges due to the lack of limitation on calls to unshare in running Pods.
Recommendations For IBM App Connect Enterprise Certified Container versions 5.0 through 12.1, upgrade the affected component to a version that mitigates the risk.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-43915

Affected Products

Ibm App Connect Enterprise Certified Container