Authentication Bypass by Spoofing in ZooKeeper - CVE-2024-51504
Published: November 6, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass IP-based authentication.
The vulnerability exists due to IPAuthenticationProvider is using the X-Forwarded-For HTTP header when authenticated users by IP address in the Admin Server. A remote attacker can pass a trusted IP addresses via the X-Forwarded-For HTTP header and gain unauthorized access to the application.
Affected software
IBM Application Suite - IBM Asset Data Dictionary Component
Big Replicate LiveData Migrator
IBM QRadar Incident Forensics
Netcool Operations Insight
IBM Process Mining
PowerVC
Oracle Enterprise Command Center Framework
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
Communications Unified Assurance
openEuler
watsonx.data
IBM Cloud Pak for Multicloud Management
zookeeper
IBM Qradar SIEM
Operational Decision Manager
How to mitigate CVE-2024-51504
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.13
Netcool Operations Insight - update to 1.6.15
IBM Process Mining - update to 2.0
PowerVC - addressed in versions 2.2.1.2, 2.3.0
watsonx.data - update to 2.1
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
Big Replicate LiveData Migrator - update to 3.2.1
zookeeper - update to 3.9.3-1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.1
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 039, 8.11.1 Interim fix 34, 8.12.0.1 Interim fix 18, 9.0.0.1 Interim fix 2
External References
Related Security Bulletins
- IP-based authentication bypass in Apache ZooKeeper
- Multiple vulnerabilities in IBM QRadar SIEM
- IBM Watson Assistant for IBM Cloud Pak for Data update for Apache ZooKeeper
- Multiple vulnerabilities in IBM Asset Data Dictionary Component
- openEuler 24.03 LTS update for zookeeper
- IBM watsonx.data update for Apache ZooKeeper
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Cloud Application Performance Management (APM)
- Multiple vulnerabilities in IBM Process Mining
- IBM PowerVC update for Apache ZooKeeper Admin Server
- Multiple vulnerabilities in IBM Big Replicate LiveData Migrator
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Oracle Enterprise Command Center Framework