Published On: Mar 13, 2024 17:28
Advisory No: TZCERT/SA/2024/03/13-03
Source: IBM
Software Affected: IBM Instana Observability
IBM has released security patches to address critical vulnerabilities affecting IBM Instana Observability. The vulnerabilities could allow an attacker to execute arbitrary code on the affected system.
IBM Instana Observability is affected with arbitrary code execution vulnerabilities as the result of sandbox escape flaw and server-side request forgery flaw in the Promise handler Node.js vm2 and Node.js IP package respectively. Successful exploitation of these vulnerabilities could allow the attacker to obtain sensitive information and execute arbitrary code on the system.
Successful exploitation of these vulnerabilities may allow the attacker to take control of affected IBM Instana Observability versions.
IBM has released patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.