当前位置:网站首页>Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
Cloud security daily 220216: root privilege escalation vulnerability found on IBM SaaS integration platform needs to be upgraded as soon as possible
2022-06-27 16:50:00 【TechWeb】
IBM App Connect Professional( Formerly known as Cast Iron) yes IBM The company will be a cloud based SaaS A platform for integrating applications with native applications . It is a drag and drop development tool for building complex integrated processes .
2 month 15 Japan ,IBM Security updates have been issued , Repair the IBM SaaS Found in the integration platform Root Privilege lifting vulnerability . Here are the details of the vulnerability :
Vulnerability Details
source : https://www.ibm.com/support/pages/node/6556738
CVE-2021-4034 CVSS score :7.8 severity : important
Polkit It may allow an attacker with local authentication to gain elevated privileges on the system , This is because pkexec Incorrect processing of parameter vectors in the utility . By making environment variables in a specific way , An attacker can exploit this vulnerability to root Authority to execute orders .
Affected products and versions
App Connect Professional 7.5.4.0
App Connect Professional 7.5.5.0
Solution
App Connect Professional 7.5.4.0 application APAR LI82497 7540 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.4.0&platform=All&function=fixId&fixids=7.5.4.0-WS-ACP-20211208-2245_H28_64-CUMUIFIX-026.vcrypt2,&includeSupersedes=0
App Connect Professional 7.5.5.0 application APAR LI82497 7550 Fix patch :
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm%2FWebSphere%2FApp+Connect+Professional&release=7.5.5.0&platform=All&function=fixId&fixids=7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.builtDockerImage,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.docker,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.vcrypt2,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-linux,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.32bit.sc-win,7.5.5.0-WS-ACP-20220208-0829_H31_64-CUMUIFIX-008.sc-win&includeSupersedes=0
View more vulnerability information And upgrade, please visit the official website :
https://www.ibm.com/blogs/psirt/
边栏推荐
- Sigkdd22 | graph generalization framework of graph neural network under the paradigm of "pre training, prompting and fine tuning"
- EMQ 助力青岛研博建设智慧水务平台
- Detailed explanation of various GPIO input and output modes (push-pull, open drain, quasi bidirectional port)
- Open source 23 things shardingsphere and database mesh have to say
- 数组表示若干个区间的集合,请你合并所有重叠的区间,并返回 一个不重叠的区间数组,该数组需恰好覆盖输入中的所有区间 。【LeetCodeHot100】
- Deeply digitise, lead cloud nativity and serve more developers
- Leetcode daily practice (Yanghui triangle)
- Adaoracle supports multi chain distributed Oracle with wide area node quotation
- Oracle概念三
- C language set operation
猜你喜欢
![[pygame Games] ce jeu](/img/3c/e573106ec91441a554cba18d5b2253.png)
[pygame Games] ce jeu "eat Everything" est fantastique? Tu manges tout? (avec code source gratuit)

Practice of constructing ten billion relationship knowledge map based on Nebula graph

Hongmeng makes efforts! HDD Hangzhou station · offline salon invites you to build ecology

Oracle concept II

Distributed session solution

【Pygame小遊戲】這款“吃掉一切”遊戲簡直奇葩了?通通都吃掉嘛?(附源碼免費領)

3.1 simple condition judgment

开源二三事|ShardingSphere 与 Database Mesh 之间不得不说的那些事

继手机之后 报道称三星也削减了电视等家电产品线的产量
P.A.R.A 方法在思源的简易应用(亲测好用)
随机推荐
全面解析零知识证明:消解扩容难题 重新定义「隐私安全」
Leetcode daily practice (longest substring without repeated characters)
Yyds dry inventory brief chrome V8 engine garbage collection
Data center table reports realize customized statistics, overtime leave summary record sharing
Adaoracle supports multi chain distributed Oracle with wide area node quotation
如何提升IT电子设备效能管理
tensorflow求解泊松方程
【牛客刷题】NowCoder号称自己已经记住了1-100000之间所有的斐波那契数。 为了考验他,我们随便出一个数n,让他说出第n个斐波那契数。如果第n个斐波那契大于6位则只取后6位。
C language teacher workload management system
Oracle概念二
Leetcode daily practice (Yanghui triangle)
Simulated process scheduling
Construction and management practice of ByteDance buried point data flow
2/14 preliminary calculation geometry
IDE Eval reset unlimited trial reset
Sliding window + monotone queue concept and example (p1886 Logu)
Domain name binding dynamic IP best practices
关于VS2019C#如何建立登陆界面输入的用户名和密码需与Access数据库的记录相匹配
Deeply digitise, lead cloud nativity and serve more developers
Four characteristics of transactions