Improper Authorization in Spring Security - CVE-2024-38821

 

Improper Authorization in Spring Security - CVE-2024-38821

Published: October 23, 2024 / Updated: October 30, 2024


Vulnerability identifier: #VU99267
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38821
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization.

The vulnerability exists due to improper implementation of authorization checks when accessing static resources in WebFlux application. A remote non-authenticated attacker can bypass authorization process and gain unauthorized access to the application.


Affected software

Spring Security
Cloud Pak for Network Automation
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
IBM Business Automation Manager Open Editions
Maximo Application Suite - Monitor Component
Big Replicate LiveData Migrator
IBM Sterling Partner Engagement Manager
IBM Sterling Control Center
IBM Process Mining
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
IBM Maximo Application Suite - AI Broker
IBM Cloud Pak for Business Automation
watsonx.data
Operational Decision Manager

How to mitigate CVE-2024-38821

Install updates from vendor's website.

Spring Security - addressed in versions 5.7.13, 5.8.15, 6.0.13, 6.1.11, 6.2.7, 6.3.4
Cloud Pak for Network Automation - update to 2.7.8
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Sterling Control Center - addressed in versions 6.3.1.0.4, 6.4.0.0.2
IBM Business Automation Manager Open Editions - update to 8.0.8
Maximo Application Suite - Monitor Component - addressed in versions 8.10.15, 8.11.13, 9.0.5
IBM Process Mining - update to 1.15.0 IF004
watsonx.data - update to 2.1.1
Big Replicate LiveData Migrator - update to 3.2.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Dell Secure Connect Gateway - update to 5.28.00.14
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 039, 8.11.1 Interim fix 34, 8.12.0.1 Interim fix 18, 9.0.0.1 Interim fix 2
IBM Maximo Application Suite - AI Broker - update to 9.0.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins