Incorrect permission assignment for critical resource in Apache Solr - CVE-2023-50292
Published: February 20, 2024
Vulnerability identifier: #VU86633
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50292
CWE-ID: CWE-732
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to incorrect permissions assignment in Solr Schema Designer when handling new Schemas and configSets. A remote attacker can load a malicious configSets and execute arbitrary code on the target system.
Affected software
Apache Solr
Log Analysis
IBM OpenPages with Watson
Operational Decision Manager
Log Analysis
IBM OpenPages with Watson
Operational Decision Manager
How to mitigate CVE-2023-50292
Install updates from vendor's website.
Apache Solr - addressed in versions 8.11.2, 9.3.0
Log Analysis - update to 1.3.8.2
IBM OpenPages with Watson - addressed in versions 8.3.0.3, 9.0.0.3
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 54, 8.11.0.1 Interim fix 29, 8.11.1 Interim fix 21, 8.12.0.1 Interim fix 3
Log Analysis - update to 1.3.8.2
IBM OpenPages with Watson - addressed in versions 8.3.0.3, 9.0.0.3
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 54, 8.11.0.1 Interim fix 29, 8.11.1 Interim fix 21, 8.12.0.1 Interim fix 3