Database/Control plane, storage & DevOps

Progress Kemp LoadMaster (including Multi-Tenancy edition): A request handler fails to validate its input before
Impact
A request handler fails to validate its input before passing it to a system call, giving an attacker OS command execution on the LoadMaster with no authentication at all. This explicitly affects the Multi-Tenancy edition — the product line built to let multiple tenants share one LoadMaster — so a single unauthenticated request can compromise the appliance underneath every tenant's virtual services on that instance.
Who can reach it
Fully remote and unauthenticated — a crafted request to the vulnerable API endpoint is sufficient, no login required.
What to do
Software upgrade to the fixed LoadMaster/Multi-Tenancy release per Kemp's advisory. Patch immediately given the unauthenticated, maximum-severity nature of this bug; if this instance is shared across tenants, treat any exposure window as a potential full-tenant-boundary breach and audit for signs of compromise, not just apply the patch.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.