Improper access control in vm2 - CVE-2022-36067

 

Improper access control in vm2 - CVE-2022-36067

Published: September 13, 2022 / Updated: April 11, 2023


Vulnerability identifier: #VU67205
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36067
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass the sandbox protections and execute arbitrary code on the host running the sandbox.


Affected software

vm2
Cloud Pak for Security (CP4S)
Multicluster Engine for Kubernetes
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2022-36067

Install updates from vendor's website.

vm2 - update to 3.9.11
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Multicluster Engine for Kubernetes - addressed in versions 2.0.2, 2.1.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.6, 2.5.2, 2.6.1
IBM Cloud Pak for Watson AIOps - update to 3.6.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins