Authentication Bypass by Spoofing in ZooKeeper - CVE-2024-51504

 

Authentication Bypass by Spoofing in ZooKeeper - CVE-2024-51504

Published: November 6, 2024


Vulnerability identifier: #VU99975
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-51504
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass IP-based authentication.

The vulnerability exists due to IPAuthenticationProvider is using the X-Forwarded-For HTTP  header when authenticated users by IP address in the Admin Server. A remote attacker can pass a trusted IP addresses via the X-Forwarded-For HTTP  header and gain unauthorized access to the application.


Affected software

ZooKeeper
IBM Application Suite - IBM Asset Data Dictionary Component
Big Replicate LiveData Migrator
IBM QRadar Incident Forensics
Netcool Operations Insight
IBM Process Mining
PowerVC
Oracle Enterprise Command Center Framework
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
Communications Unified Assurance
openEuler
watsonx.data
IBM Cloud Pak for Multicloud Management
zookeeper
IBM Qradar SIEM
Operational Decision Manager

How to mitigate CVE-2024-51504

Install updates from vendor's website.

ZooKeeper - update to 3.9.3
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.13
Netcool Operations Insight - update to 1.6.15
IBM Process Mining - update to 2.0
PowerVC - addressed in versions 2.2.1.2, 2.3.0
watsonx.data - update to 2.1
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
Big Replicate LiveData Migrator - update to 3.2.1
zookeeper - update to 3.9.3-1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.1
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 039, 8.11.1 Interim fix 34, 8.12.0.1 Interim fix 18, 9.0.0.1 Interim fix 2

External References

Related Security Bulletins