SB2023052905 - Code injection in IBM App Connect Enterprise Certified Container



SB2023052905 - Code injection in IBM App Connect Enterprise Certified Container

Published: May 29, 2023 Updated: December 18, 2023

Security Bulletin ID SB2023052905
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Code injection (CVE-ID: CVE-2023-30547)

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to an error in exception sanitization. A remote user can raise an unsanitized host exception inside "handleException()", which can be used to escape the sandbox and run arbitrary code in host context.


Remediation

Install update from vendor's website.