当前位置:网站首页>Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
2022-06-27 16:50:00 【TechWeb】
IBM App Connect Professional( Formerly known as Cast Iron) yes IBM The company will be a cloud based SaaS A platform for integrating applications with native applications . It is a drag and drop development tool for building complex integrated processes .
2 month 15 Japan ,IBM Security updates have been issued , Repair the IBM SaaS Found in the integration platform Root Privilege lifting vulnerability . Here are the details of the vulnerability :
Vulnerability Details
source : https://www.ibm.com/support/pages/node/6556738
CVE-2021-4034 CVSS score :7.8 severity : important
Polkit It may allow an attacker with local authentication to gain elevated privileges on the system , This is because pkexec Incorrect processing of parameter vectors in the utility . By making environment variables in a specific way , An attacker can exploit this vulnerability to root Authority to execute orders .
Affected products and versions
App Connect Professional 7.5.4.0
App Connect Professional 7.5.5.0
Solution
App Connect Professional 7.5.4.0 application APAR LI82497 7540 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.4.0&platform=All&function=fixId&fixids=7.5.4.0-WS-ACP-20211208-2245_H28_64-CUMUIFIX-026.vcrypt2,&includeSupersedes=0
App Connect Professional 7.5.5.0 application APAR LI82497 7550 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.5.0&platform=All&function=fixId&fixids=7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.builtDockerImage,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.docker,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.vcrypt2,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-win,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-win&includeSupersedes=0
View more vulnerability information And upgrade, please visit the official website :
https://www.ibm.com/blogs/psirt/
边栏推荐
- LeetCode每日一练(主要元素)
- The two trump brand products of Langjiu are resonating in Chengdu, continuously driving the consumption wave of bottled liquor
- Mihayou sued Minmetals trust, which was exposed to product thunderstorms
- Oracle concept 3
- The time of localdatetime type (2019-11-19t15:16:17) is queried with the time range of Oracle
- Sigkdd22 | graph generalization framework of graph neural network under the paradigm of "pre training, prompting and fine tuning"
- 深耕数字化,引领云原生,服务更多开发者
- 郎酒两大王牌产品成都联动共振,持续带动光瓶酒消费浪潮
- 华为云DevCloud重磅发布四大新能力,创下国内两项第一
- 鴻蒙發力!HDD杭州站·線下沙龍邀您共建生態
猜你喜欢

IDE Eval reset unlimited trial reset

# Cesium实现卫星在轨绕行
![[pygame Games] ce jeu](/img/3c/e573106ec91441a554cba18d5b2253.png)
[pygame Games] ce jeu "eat Everything" est fantastique? Tu manges tout? (avec code source gratuit)

模拟进程调度

List to table

Leetcode daily practice (main elements)

Popularization of MCU IO port: detailed explanation of push-pull output and open drain output

Oracle概念二

Leetcode daily practice (Yanghui triangle)

Introduce you to ldbc SNB, a powerful tool for database performance and scenario testing
随机推荐
分布式Session解决方案
A distribution fission activity is more than just a circle of friends!
Kubernetes基础自学系列 | Ingress API讲解
A large number of missing anchor text
#yyds干货盘点# 解决剑指offer:二叉树中和为某一值的路径(三)
Deeply digitise, lead cloud nativity and serve more developers
Openssf security plan: SBOM will drive software supply chain security
A distribution fission activity is more than just a circle of friends!
数组表示若干个区间的集合,请你合并所有重叠的区间,并返回 一个不重叠的区间数组,该数组需恰好覆盖输入中的所有区间 。【LeetCodeHot100】
QT5 之信号与槽机制(演示控件自带的信号与槽函数关联)
Extract field year / quarter effect based on date
Oracle concept 3
P.A.R.A 方法在思源的简易应用(亲测好用)
关于#mysql#的问题:问题遇到的现象和发生背景
MySQL中符号@的作用
Logstash excludes specific files or folders from collecting report log data
Leetcode daily practice (sum of two numbers)
等保三级密码复杂度是多少?多久更换一次?
Alibaba cloud liupeizi: Inspiration from cloud games - innovation on the end
[multithreading] thread communication scheduling, waiting set wait(), notify()