Security Bulletin: IBM Watson CP4D Data Stores is vulnerable to Elastic Elasticsearch sensitive information disclosure vulnerabilitiy( CVE-2024-23451)
Discription

Summary Potential Elastic Elasticsearch sensitive information disclosure vulnerabilitiy( CVE-2024-23451) has been identified that may affect IBM Watson CP4D Data Stores. The vulnerability have been addressed. Refer to details for additional information. Vulnerability Details ** CVEID: CVE-2024-23451 DESCRIPTION: **Elastic Elasticsearch could allow a remote authenticated attacker to obtain sensitive information, caused by incorrect authorization issue in the API key based security model for Remote Cluster Security. By sending a specially crafted request, a remote attacker could exploit this vulnerability to read arbitrary documents from any index on the remote cluster. CVSS Base score: 4.4 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/286648 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N) Affected Products and Versions Affected Product(s)| Version(s) —|— Watson CP4D Data Stores| 4.0.0 – 5.0.2 Remediation/Fixes For all affected versions, IBM strongly recommends addressing the vulnerability now by upgrading to the latest release (v5.0.3 or later releases) of IBM Watson CP4D Data Stores which maintains backward compatibility with the versions listed above. Product Latest Version| Remediation/Fix/Instructions —|— IBM Watson CP4D Data Stores 5.0.3| Follow instructions for Installing IBM Watson CP4D Data Stores in Link to Release (v5.0.3 or later releases) release information….Read More

Back to Main

Subscribe for the latest news: