Improper access control in Apache Kafka - CVE-2018-17196
Published: July 17, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper security restrictions imposed by the affected software. A remote authenticated attacker with write permission on respective topics can send a crafted Produce request that is designed to bypass transaction/idempotent access control list (ACL) validation.
Affected software
Log Analysis
Primavera P6 Enterprise Project Portfolio Management
IBM Qradar SIEM
Primavera Unifier
IBM Sterling Order Management
How to mitigate CVE-2018-17196
Log Analysis - update to 1.3.7.2 IF003
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
IBM Sterling Order Management - update to 10.0.0.29
External References
Related Security Bulletins
- Security restrictions bypass in Apache Kafka
- Multiple vulnerabilities in Primavera P6 Enterprise Project Portfolio Management
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Sterling Order Management
- IBM Log Analysis update for Apache Kafka
- Multiple vulnerabilities in IBM QRadar SIEM