QID 91894
Date Published: 2022-05-10
QID 91894: Microsoft Insight Software - Magnitude Simba Amazon Redshift ODBC Driver Remote Code Execution (RCE) Vulnerability
Azure Data Factory is a Microsoft Cloud Extract Transform Load (ETL) service that enables data integration and data transformation.
Customers using standalone Azure Data Factory can create an Integration Runtime (IR) in their factories and/or workspaces to allow for data integration across different network environments.
QID Detection Logic: (Authenticated)
It checks InsightSoftware package versions to check for the vulnerable packages.
Customers using Azure Data Factory with Self-hosted IRs (SHIRs) with auto-update turned off must update their SHIRs to the latest version (5.17.8154.2)
The vulnerability could have allowed an attacker to perform remote command execution across IR infrastructure not limited to a single tenant.
Solution
Customers using Azure Data Factory with Self-hosted IRs (SHIRs) with auto-update turned off are advised to upgrade to version 5.17.8154.2
Vendor References
- CVE-2022-29972 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29972
CVEs related to QID 91894
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-29972 |
|