Skip to content

OMI Remote Code Execution Vulnerability

Critical
ankurgupta2212 published GHSA-fmh7-p6gp-8xpj Sep 30, 2021

Package

OMI (DEB)

Affected versions

<1.6.8-1

Patched versions

1.6.8-1

Description

Description

Microsoft is releasing this security advisory to provide information about a vulnerability in OMI.
Fixes have been released for three Elevation of Privilege (EoP) vulnerabilities and one unauthenticated Remote Code Execution (RCE) vulnerability in the Open Management Infrastructure (OMI) framework: CVE-2021-38645, CVE-2021-38649, CVE-2021-38648, and CVE-2021-38647.
All customers using OMI with a version below 1.6.8-1 are impacted.

Patches

The issues have been patched in OMI version 1.6.8-1. All versions >1.6.8-1 are safe from these vulnerabilities.

Workarounds

None

References

If you have any questions or comments about this advisory, refer to the link here

Severity

Critical

CVE ID

CVE-2021-38647

Weaknesses

No CWEs