Information disclosure in Apache Kafka Clients - CVE-2024-31141

 

Information disclosure in Apache Kafka Clients - CVE-2024-31141

Published: November 21, 2024 / Updated: February 11, 2025


Vulnerability identifier: #VU100780
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31141
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to the way Apache Kafka Clients handles custom configurations. A remote user with access to REST API can read arbitrary files and variables on the system and escalate their privileges filesystem/environment access.


Affected software

Apache Kafka Clients
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
IBM Operator for Apache Flink
Netcool Operations Insight
IBM Process Mining
IBM Fusion HCI
Splunk User Behavior Analytics (UBA)
IBM Sterling B2B Integrator
Oracle Communications Unified Inventory Management
IBM Automation Decision Services
IBM Business Automation Workflow
IBM Observability with Instana
Log Analysis
App Connect Enterprise Certified Container
IBM Spectrum Control
IBM Maximo Application Suite - Manage Component
IBM InfoSphere Information Server for Cloud
IBM Cloud Pak for Business Automation
IBM Disconnected Log Collector
watsonx.data
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Business Automation Manager Open Editions
Integration Bus for z/OS
InfoSphere Data Replication
watsonx Assistant for IBM Cloud Pak for Data
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
webMethods BPM
Guardium Data Protection
Business Automation Insights
Communications Unified Assurance
IBM Sterling File Gateway
IBM Qradar SIEM
AMQ Streams
Operational Decision Manager
IBM InfoSphere Information Server

How to mitigate CVE-2024-31141

Install updates from vendor's website.

Apache Kafka Clients - addressed in versions 3.5.2, 3.6.2, 3.7.0
IBM Operator for Apache Flink - update to 1.4.5
Netcool Operations Insight - update to 1.6.15
IBM Disconnected Log Collector - update to 1.8.7
IBM Process Mining - update to 2.0
watsonx.data - update to 2.1.1
IBM Fusion HCI - update to 2.11.0
Guardium Data Security Center (GDSC) - update to 3.8.5
Security QRadar EDR - update to 3.12.15
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0
IBM Sterling File Gateway - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 13
IBM Business Automation Manager Open Editions - update to 8.0.7
Integration Bus for z/OS - update to 10.1.0.5
IBM App Connect Enterprise - update to 12.0.12.8
IBM Automation Decision Services - update to 24.0.0.0.4
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF001
IBM Observability with Instana - update to 286
Log Analysis - update to 1.3.8.1
AMQ Streams - update to 2
Red Hat Camel for Spring Boot - update to 4.8
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
App Connect Enterprise Certified Container - addressed in versions 5.0.22, 12.0.6, 12.4.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
IBM Spectrum Control - update to 5.4.13
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.21, 8.7.15, 9.0.8
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 42, 8.11.1.0 Interim fix 39, 8.12.0.1 Interim fix 24, 9.0.0.1 Interim fix 7
webMethods BPM - update to 11.1 Fix 9
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 6
IBM InfoSphere Information Server for Cloud - update to 11.7.1 Fix Pack 6
Guardium Data Protection - update to 12.0p35
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Business Automation Insights - addressed in versions 24.0.0.0.2, 24.0.1.0.1

External References

Related Security Bulletins