Improper Authorization in Spring Security - CVE-2024-38827

 

Improper Authorization in Spring Security - CVE-2024-38827

Published: November 19, 2024


Vulnerability identifier: #VU100676
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38827
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to presence of Locale dependent exceptions when using String.toLowerCase() and String.toUpperCase() for string comparison. A remote attacker can bypass authorization rules using specially crafted input.

Note, the vulnerability is related to #VU98795 (CVE-2024-38820).


Affected software

Spring Security
Netcool Operations Insight
IBM Cloud Pak for Security
IBM Process Mining
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
IBM Spectrum Symphony
Oracle Communications Unified Inventory Management
Oracle Financial Services Model Management and Governance
IBM Common Licensing
IBM Maximo Application Suite - AI Broker
Oracle SD-WAN Edge
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
QRadar Suite
watsonx.data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
DevOps Solution Workbench
IBM Business Automation Manager Open Editions
Oracle Business Intelligence Enterprise Edition
Telco Service Design Configuration Designer
Telco Unified OSS Console
Telco Service Orchestrator
Telco Network Function Virtualization Orchestrator
Guardium Data Protection
IBM Sterling File Gateway
Oracle Financial Services Compliance Studio
IBM Cognos Controller
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Network Slice Selection Function
Operational Decision Manager

How to mitigate CVE-2024-38827

Install updates from vendor's website.

Spring Security - addressed in versions 5.7.14, 5.8.16, 6.0.14, 6.1.12, 6.2.8, 6.3.5
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Process Mining - update to 2.0
watsonx.data - update to 2.1.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0
IBM Sterling File Gateway - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Spectrum Symphony - update to 7.3.2 FP3
IBM Business Automation Manager Open Editions - update to 8.0.8
IBM Common Licensing - update to 9.0.0.2
IBM Maximo Application Suite - AI Broker - update to 9.0.5
IBM Cognos Controller - update to 11.1.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
Telco Service Design Configuration Designer - update to 2.3.0
Telco Unified OSS Console - update to 3.1.15
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Telco Service Orchestrator - update to 5.2.1
Telco Network Function Virtualization Orchestrator - update to 7.3.0
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 039, 8.11.1 Interim fix 34, 8.12.0.1 Interim fix 18, 9.0.0.1 Interim fix 2
Guardium Data Protection - addressed in versions 11.0p580, 12.0p55, 12.0p140, 12.2.1

External References

Related Security Bulletins