Vulnerability Details
Basic Information
| Title | Security Bulletin: Vulnerabilities in Apache Solr (lucene) and Apache ZooKeeper affect IBM Operations Analytics – Log Analysis (CVE-2024-23454, CVE-2024-30171, CVE-2024-23944) |
|---|---|
| Type | ibm |
| Published | 2025-04-25T16:00:41 |
| Last Seen | 2025-04-25T18:56:28 |
| CVSS Score | 6.2 (MEDIUM) |
CVSS v3 Details
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2024-23454, CVE-2024-23944, CVE-2024-30171 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
There are vulnerabilities in Bouncy Castle, Apache Hadoop that potentially expose sensitive information that affect Apache Solr and Apache ZooKeeper used by IBM Operations Analytics – Log Analysis
## Vulnerability Details
**CVEID:**CVE-2024-23454
**DESCRIPTION:** Apache Hadoop could allow a local authenticated attacker to obtain sensitive information, caused by not set permissions for temporary directory by default in the RunJar.run() function. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
**CWE:**CWE-269: Improper Privilege Management
**CVSS Source:** IBM X-Force
**CVSS Base score:** 3.3
**CVSS Vector:**(CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
**CVEID:**CVE-2024-30171
**DESCRIPTION:** The Bouncy Castle Crypto Package For Java could allow a remote authenticated attacker to obtain sensitive information, caused by a flaw in the RSA decryption (both PKCS#1v1.5 and OAEP) feature. By utilize timing side-channel attack techniques, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
**CWE:**CWE-203: Observable Discrepancy
**CVSS Source:** IBM X-Force
**CVSS Base score:** 5.3
**CVSS Vector:**(CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
**CVEID:**CVE-2024-23944
**DESCRIPTION:** Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKeeper server doesn’t do ACL check when the persistent watcher is triggered and as a consequence, the full path of znodes that a watch event gets triggered upon is exposed to the owner of the watcher. It’s important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical. Users are recommended to upgrade to version 3.9.2, 3.8.4 which fixes the issue.
**CWE:**CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
**CVSS Source:** IBM X-Force
**CVSS Base score:** 4.3
**CVSS Vector:**(CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
## Affected Products and Versions
Affected Product(s)| Version(s)
—|—
Log Analysis| 1.3.7.0.
Log Analysis| 1.3.7.1
Log Analysis| 1.3.7.2
Log Analysis| 1.3.8.0
Log Analysis| 1.3.8.1
## Remediation/Fixes
Principal Product and Version(s)| Fix details
—|—
IBM Operations Analytics – Log Analysis version 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1| IBM strongly recommend addressing the vulnerability now by applying 1.3.8.2 (1.3.8-TIV-IOALA-FP2) or a later fix pack available from IBM fix central
## Workarounds and Mitigations
None
##
Impact Assessment
| Base Score | 6.2 |
|---|---|
| Severity | MEDIUM |