API Connect has addressed the following vulnerability.
CVEID: CVE-2019-5736 DESCRIPTION: Runc could allow a local attacker to execute arbitrary commands on the system, caused by the improper handling of system file descriptors when running containers. An attacker could exploit this vulnerability using a malicious container to overwrite the contents of the host runc binary and execute arbitrary commands with root privileges on the host system.
CVSS Base Score: 7.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156819> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
Affected API Connect | Affected Versions |
---|---|
IBM API Connect | 2018.1-2018.4.1.2 |
Affected Product | Addressed in VRMF | APAR | Remediation / First Fix |
---|
IBM API Connect
2018.4.1.-2018.4.1.2
| 2018.4.1.3 fixpack | LI80651 |
Addressed in IBM API Connect V2018.4.1.3 fixpack
The Open Virtual Appliance (OVA) packages for Management Server, Developer Portal and Analytics are impacted.
Follow this link and find the OVA packages: