Werk #16249: mk_informix: Follow up for Werk 16198
| Component | Checks & agents | ||||||||
| Title | mk_informix: Follow up for Werk 16198 | ||||||||
| Date | Jul 26, 2024 | ||||||||
| Level | Trivial Change | ||||||||
| Class | Security Fix | ||||||||
| Compatibility | Compatible - no manual interaction needed | ||||||||
| Checkmk versions & editions |
|
Werk #16198 addressed potential priviledge escalation by the agent plugin mk_informix.
However, a few callsites to the binaries dbaccess and onstat where missing the safe execution.
Those binaries are now also called in a safe way.
Vulnerability Management:
We have rated the issue with a CVSS Score of 5.2 (Medium) with the following CVSS vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H and assigned CVE CVE-2024-28829.