8.1
CVE-2022-43915
- EPSS 0.11%
- Published 24.08.2024 12:15:04
- Last modified 21.09.2024 10:15:04
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with privileged access to execute commands in a running Pod to elevate their user privileges.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ App Connect Enterprise Certified Container Version5.0 SwEditionlts
Ibm ≫ App Connect Enterprise Certified Container Version7.1
Ibm ≫ App Connect Enterprise Certified Container Version7.2
Ibm ≫ App Connect Enterprise Certified Container Version8.0
Ibm ≫ App Connect Enterprise Certified Container Version8.1
Ibm ≫ App Connect Enterprise Certified Container Version8.2
Ibm ≫ App Connect Enterprise Certified Container Version9.0
Ibm ≫ App Connect Enterprise Certified Container Version9.1
Ibm ≫ App Connect Enterprise Certified Container Version9.2
Ibm ≫ App Connect Enterprise Certified Container Version10.0
Ibm ≫ App Connect Enterprise Certified Container Version10.1
Ibm ≫ App Connect Enterprise Certified Container Version11.0
Ibm ≫ App Connect Enterprise Certified Container Version11.1
Ibm ≫ App Connect Enterprise Certified Container Version11.2
Ibm ≫ App Connect Enterprise Certified Container Version11.3
Ibm ≫ App Connect Enterprise Certified Container Version11.4
Ibm ≫ App Connect Enterprise Certified Container Version11.5
Ibm ≫ App Connect Enterprise Certified Container Version11.6
Ibm ≫ App Connect Enterprise Certified Container Version12.0 SwEditionlts
Ibm ≫ App Connect Enterprise Certified Container Version12.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.299 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
psirt@us.ibm.com | 6.8 | 1.6 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.