Permissions, Privileges, and Access Controls in Hadoop - CVE-2018-8029
Published: June 6, 2019
Vulnerability identifier: #VU18689
CSH Severity: High
CVSS v4: 9.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2018-8029
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to improper access restrictions for the API interface. A remote authenticated user can use vulnerable API endpoint to execute arbitrary YARN commands on the system as root.
Affected software
Hadoop
IBM Qradar SIEM
watsonx.data
IBM Cloud Application Performance Management (APM)
IBM InfoSphere Information Server
IBM Qradar SIEM
watsonx.data
IBM Cloud Application Performance Management (APM)
IBM InfoSphere Information Server
How to mitigate CVE-2018-8029
Install updates from vendor's website.
Hadoop - addressed in versions 2.8.5, 2.9.2, 3.1.1
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
watsonx.data - update to 2.0.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
watsonx.data - update to 2.0.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
- https://lists.apache.org/thread.html/0b8d58e02dbd0fb8bf7320c514fe58da1d6728bdc150f1ba04e0d9fc@%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/17084c09e6dedf60efe08028b429c92ffd28aacc28454e4fa924578a@%3Cgeneral.hadoop.apache.org%3E
- https://lists.apache.org/thread.html/a0164b87660223a2d491f83c88f905fe1a9fa8dc795148d9b0d968c8@%3Cdev.hbase.apache.org%3E
- https://lists.apache.org/thread.html/a97c53a81e639ca2fc7b8f61a4fcd1842c2a78544041244a7c624727@%3Cissues.hbase.apache.org%3E
Related Security Bulletins
- Privilege escalation in Apache Hadoop
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM watsonx.data