Improper access control in ZooKeeper - CVE-2024-23944

 

Improper access control in ZooKeeper - CVE-2024-23944

Published: March 15, 2024


Vulnerability identifier: #VU87570
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23944
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in persistent watchers. A remote user can bypass implemented security restrictions and obtain user names or login identifiers.


Affected software

ZooKeeper
IBM Observability with Instana
Log Analysis
PowerVC
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cloud Pak for Security
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Watson Discovery for IBM Cloud Pak for Data
Tivoli Network Manager IP Edition
DataStage on Cloud Pak for Data
IBM Security Verify Information Queue
Business Automation Insights
Netezza Performance Server Replication Services
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
IBM QRadar Incident Forensics
IBM Qradar SIEM
Event Streams
IBM Watson Explorer Foundational Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
Primavera Unifier
Stream Analytics
Planning Analytics Local
watsonx.data
AMQ Streams
HPE Unified OSS Console (UOC)

How to mitigate CVE-2024-23944

Install updates from vendor's website.

ZooKeeper - addressed in versions 3.8.4, 3.9.2
IBM Observability with Instana - update to 1.0.297
Log Analysis - update to 1.3.8.2
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 5.0.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
IBM Security Verify Information Queue - update to 10.0.9
IBM Watson Explorer Foundational Components - update to 11.0.2.19
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.15
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Cloud Pak for Security - update to 1.11.2.0
Planning Analytics Local - addressed in versions 2.0.0.96, 2.1.3
watsonx.data - update to 2.0.3
AMQ Streams - addressed in versions 2.5.2, 2.7.0
Netezza Performance Server Replication Services - update to 3.0.5.0
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.12
HPE Unified OSS Console (UOC) - update to 3.1.12
IBM Cloud Pak for Watson AIOps - update to 4.6.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
User Entity Behavior Analytics - update to 5.0.2
IBM QRadar Incident Forensics - update to 7.5.0.10
Event Streams - update to 11.5.1

External References

Related Security Bulletins