Security restrictions bypass in Thrift - CVE-2018-1320

 

Security restrictions bypass in Thrift - CVE-2018-1320

Published: January 13, 2019


Vulnerability identifier: #VU16954
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1320
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to bypass security restrictions.

The vulnerability exists due to unspecified flaw. A remote attacker can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.


Affected software

Thrift
IBM Integration Bus
Netcool Operations Insight
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
Fuse
IBM Security Guardium

How to mitigate CVE-2018-1320

Update to version 0.12.0.

Thrift - update to 0.12.0
Fuse - update to 7.4.0
Netcool Operations Insight - update to 1.6.7
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins