当前位置:网站首页>Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
2022-06-27 16:50:00 【TechWeb】
IBM App Connect Professional( Formerly known as Cast Iron) yes IBM The company will be a cloud based SaaS A platform for integrating applications with native applications . It is a drag and drop development tool for building complex integrated processes .
2 month 15 Japan ,IBM Security updates have been issued , Repair the IBM SaaS Found in the integration platform Root Privilege lifting vulnerability . Here are the details of the vulnerability :
Vulnerability Details
source : https://www.ibm.com/support/pages/node/6556738
CVE-2021-4034 CVSS score :7.8 severity : important
Polkit It may allow an attacker with local authentication to gain elevated privileges on the system , This is because pkexec Incorrect processing of parameter vectors in the utility . By making environment variables in a specific way , An attacker can exploit this vulnerability to root Authority to execute orders .
Affected products and versions
App Connect Professional 7.5.4.0
App Connect Professional 7.5.5.0
Solution
App Connect Professional 7.5.4.0 application APAR LI82497 7540 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.4.0&platform=All&function=fixId&fixids=7.5.4.0-WS-ACP-20211208-2245_H28_64-CUMUIFIX-026.vcrypt2,&includeSupersedes=0
App Connect Professional 7.5.5.0 application APAR LI82497 7550 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.5.0&platform=All&function=fixId&fixids=7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.builtDockerImage,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.docker,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.vcrypt2,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-win,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-win&includeSupersedes=0
View more vulnerability information And upgrade, please visit the official website :
https://www.ibm.com/blogs/psirt/
边栏推荐
- Introduce you to ldbc SNB, a powerful tool for database performance and scenario testing
- 关于#mysql#的问题:问题遇到的现象和发生背景
- 3.3 one of the fixed number of cycles
- Hierarchical clustering and case analysis
- [pyGame games] this "eat everything" game is really wonderful? Eat them all? (with source code for free)
- ICML 2022 ぷ the latest fedformer of the Dharma Institute of Afghanistan ⻓ surpasses SOTA in the whole process of time series prediction
- [Niuke's questions] nowcoder claims to have remembered all Fibonacci numbers between 1 and 100000. To test him, we gave him a random number N and asked him to say the nth Fibonacci number. If the nth
- Mobile terminal click penetration
- 关于VS2019C#如何建立登陆界面输入的用户名和密码需与Access数据库的记录相匹配
- 等保2.0密码要求是什么?法律依据有哪些?
猜你喜欢

Source NAT address translation and server mapping web page configuration of firewall Foundation

List to table

IDE Eval reset unlimited trial reset

Sigkdd22 | graph generalization framework of graph neural network under the paradigm of "pre training, prompting and fine tuning"
#yyds干货盘点#简述chromeV8引擎垃圾回收

Slow bear market, bit Store provides stable stacking products to help you cross the bull and bear
P. Simple application of a.r.a method in Siyuan (friendly testing)

Leetcode daily practice (Yanghui triangle)

米哈游起诉五矿信托,后者曾被曝产品暴雷

Alibaba cloud liupeizi: Inspiration from cloud games - innovation on the end
随机推荐
Special function calculator
LeetCode每日一练(无重复字符的最长子串)
QT audio playback upgrade (7)
P4251 [scoi2015] small convex play matrix (still a little confused)
A distribution fission activity is more than just a circle of friends!
全面解析零知识证明:消解扩容难题 重新定义「隐私安全」
实现简单的三D立方体自动旋转
QT5.5.1桌面版安装配置过程中的疑难杂症处理(配置ARM编译套件)
关于VS2019C#如何建立登陆界面输入的用户名和密码需与Access数据库的记录相匹配
The interview lasted for half a year. Last month, I successfully got Alibaba p7offer. It was all because I chewed the latest interview questions in 2020!
Oracle concept 3
Etcd visualization tool: kstone deployment (I), rapid deployment based on Helm
LeetCode每日一练(两数之和)
Leetcode daily practice (Yanghui triangle)
域名绑定动态IP最佳实践
ORM表关系及操作
P. Simple application of a.r.a method in Siyuan (friendly testing)
About MySQL: the phenomenon and background of the problem
Domain name binding dynamic IP best practices
Detailed explanation of transaction isolation level