PT-2024-11667 · Ibm · Ibm App Connect Enterprise Certified Container

CVE-2022-43915

·

Published

2024-08-24

·

Updated

2024-09-21

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM App Connect Enterprise Certified Container versions 5.0 through 12.1
Description The issue allows a user with privileged access to execute commands in a running Pod, potentially elevating their user privileges due to the lack of limitation on calls to unshare in running Pods.
Recommendations For IBM App Connect Enterprise Certified Container versions 5.0 through 12.1, upgrade the affected component to a version that mitigates the risk.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-43915

Affected Products

Ibm App Connect Enterprise Certified Container