Improper Privilege Management in Cassandra - CVE-2023-30601

 

Improper Privilege Management in Cassandra - CVE-2023-30601

Published: May 30, 2023


Vulnerability identifier: #VU76636
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30601
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper privilege management when enabling FQL/Audit logs. A remote user with JMX access can execute arbitrary OS commands with privileges of the server.


Affected software

Cassandra
IBM InfoSphere Information Server
IBM Cloud Pak for Multicloud Management Monitoring
IBM InfoSphere Information Server for Cloud
IBM Cloud Pak for Watson AIOps
IBM Sterling Global Mailbox (GM)

How to mitigate CVE-2023-30601

Install updates from vendor's website.

Cassandra - addressed in versions 4.0.10, 4.1.2
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Cloud Pak for Watson AIOps - update to 4.1
IBM Sterling Global Mailbox (GM) - addressed in versions 6.1.2.3, 6.2.0.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM InfoSphere Information Server for Cloud - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins