Improper access control in Spring Security - CVE-2024-22257
Published: March 19, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions when the "AuthenticatedVoter#vote" passing a "null" Authentication parameter. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
Confluence Server
Confluence Data Center
Crucible Server
Crucible Data Center
Crowd Data Center
Jira Service Management Data Center
Jira Service Management Server
Oracle Communications Unified Inventory Management
Bitbucket Data Center
Bamboo Server
Jira Software Data Center
Oracle SD-WAN Edge
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
webMethods Managed File Transfer
Cloud Pak for Network Automation
Storage Resource Manager
Dell Policy Manager for Secure Connect Gateway (SCG)
IBM Sterling Connect:Direct for Microsoft Windows
Maximo Application Suite - Monitor Component
Dell Data Protection Central
Crowd Server
MySQL Enterprise Monitor
Bitbucket Server
Jira Software Server
Oracle Insurance Policy Administration
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Console
QRadar Suite
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
How to mitigate CVE-2024-22257
Confluence Server - addressed in versions 7.19.22, 8.5.9, 8.9.1
Confluence Data Center - addressed in versions 7.19.22, 8.5.9, 8.9.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Crucible Server - update to 4.9.11
Crucible Data Center - update to 4.9.11
Crowd Data Center - addressed in versions 5.0.11, 5.1.9, 5.2.4
Crowd Server - addressed in versions 5.0.11, 5.1.9, 5.2.4
Jira Service Management Data Center - addressed in versions 5.4.20, 5.12.7, 5.15.2
Jira Service Management Server - addressed in versions 5.4.20, 5.12.7, 5.15.2
Bitbucket Data Center - addressed in versions 8.9.12, 8.19.1
Bitbucket Server - addressed in versions 8.9.12, 8.19.1
Bamboo Server - addressed in versions 9.2.13, 9.5.3, 9.6.1
Jira Software Data Center - addressed in versions 9.4.20, 9.12.7, 9.15.2
Jira Software Server - addressed in versions 9.4.20, 9.12.7, 9.15.2
QRadar Suite - update to 1.10.22.0
Cloud Pak for Network Automation - update to 2.7.5
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.4
Storage Resource Manager - update to 5.0.2.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
IBM Sterling Connect:Direct for Microsoft Windows - update to 6.3.0.3 iFix002
Dell EMC VxRail Appliance - update to 8.0.311
Maximo Application Suite - Monitor Component - addressed in versions 8.10.9, 8.11.6
Dell Data Protection Central - update to 19.11.0-2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
IBM Automation Decision Services - update to 23.0.2.0.4
External References
Related Security Bulletins
- Improper access control in Spring Security
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Bamboo Data Center and Server update for Spring Security
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Automation Decision Services
- Bitbucket Data Center and Server update for Spring Security
- Jira Software Data Center and Server update for spring-security-core
- Jira Service Management Data Center and Server update for spring-security-core
- Crowd Data Center and Server update for spring-security-core
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Confluence Data Center and Server update for spring-security-core
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Improper access control in Oracle Communications Unified Inventory Management
- Multiple vulnerabilities in Oracle Insurance Policy Administration J2EE
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell VxRail Appliance
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Spring Security
- Multiple vulnerabilities in Crucible Data Center and Crucible Server