当前位置:网站首页>Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
2022-06-27 16:50:00 【TechWeb】
IBM App Connect Professional( Formerly known as Cast Iron) yes IBM The company will be a cloud based SaaS A platform for integrating applications with native applications . It is a drag and drop development tool for building complex integrated processes .
2 month 15 Japan ,IBM Security updates have been issued , Repair the IBM SaaS Found in the integration platform Root Privilege lifting vulnerability . Here are the details of the vulnerability :
Vulnerability Details
source : https://www.ibm.com/support/pages/node/6556738
CVE-2021-4034 CVSS score :7.8 severity : important
Polkit It may allow an attacker with local authentication to gain elevated privileges on the system , This is because pkexec Incorrect processing of parameter vectors in the utility . By making environment variables in a specific way , An attacker can exploit this vulnerability to root Authority to execute orders .
Affected products and versions
App Connect Professional 7.5.4.0
App Connect Professional 7.5.5.0
Solution
App Connect Professional 7.5.4.0 application APAR LI82497 7540 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.4.0&platform=All&function=fixId&fixids=7.5.4.0-WS-ACP-20211208-2245_H28_64-CUMUIFIX-026.vcrypt2,&includeSupersedes=0
App Connect Professional 7.5.5.0 application APAR LI82497 7550 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.5.0&platform=All&function=fixId&fixids=7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.builtDockerImage,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.docker,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.vcrypt2,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-win,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-win&includeSupersedes=0
View more vulnerability information And upgrade, please visit the official website :
https://www.ibm.com/blogs/psirt/
边栏推荐
- 10分钟掌握mysql的安装步骤
- Julia constructs diagonal matrix
- Oracle concept 3
- 华为云DevCloud重磅发布四大新能力,创下国内两项第一
- Special function calculator
- Autodesk NavisWorks 2022 software installation package download and installation tutorial
- Introduce you to ldbc SNB, a powerful tool for database performance and scenario testing
- Detailed explanation of various GPIO input and output modes (push-pull, open drain, quasi bidirectional port)
- Qt5 signal and slot mechanism (demonstrate the correlation between the control's own signal and slot function)
- Annual comprehensive analysis of China's audio market in 2022
猜你喜欢
随机推荐
logstash排除特定文件或文件夹不采集上报日志数据
QT audio playback upgrade (7)
模拟进程调度
字节跳动埋点数据流建设与治理实践
Autodesk NavisWorks 2022 software installation package download and installation tutorial
Construction and management practice of ByteDance buried point data flow
Realize simple three-D cube automatic rotation
【牛客刷题】NowCoder号称自己已经记住了1-100000之间所有的斐波那契数。 为了考验他,我们随便出一个数n,让他说出第n个斐波那契数。如果第n个斐波那契大于6位则只取后6位。
Impressive questions
Logstash excludes specific files or folders from collecting report log data
P. Simple application of a.r.a method in Siyuan (friendly testing)
开源二三事|ShardingSphere 与 Database Mesh 之间不得不说的那些事
C語言教師工作量管理系統
What are the password requirements for waiting insurance 2.0? What are the legal bases?
Sliding window + monotone queue concept and example (p1886 Logu)
3.3 one of the fixed number of cycles
Redis系列2:数据持久化提高可用性
How to modify / display GPIO status through ADB shell
Julia constructs diagonal matrix
Oracle概念二









