Improper access control in Apache Kafka - CVE-2018-17196

 

Improper access control in Apache Kafka - CVE-2018-17196

Published: July 17, 2019


Vulnerability identifier: #VU19218
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17196
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.

The vulnerability exists due to improper security restrictions imposed by the affected software. A remote authenticated attacker with write permission on respective topics can send a crafted Produce request that is designed to bypass transaction/idempotent access control list (ACL) validation.


Affected software

Apache Kafka
Log Analysis
Primavera P6 Enterprise Project Portfolio Management
IBM Qradar SIEM
Primavera Unifier
IBM Sterling Order Management

How to mitigate CVE-2018-17196

Install updates from vendor's website.

Apache Kafka - update to 2.1.1
Log Analysis - update to 1.3.7.2 IF003
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
IBM Sterling Order Management - update to 10.0.0.29

External References

Related Security Bulletins