SB2021092812 - IBM Security SOAR update for Elasticsearch



SB2021092812 - IBM Security SOAR update for Elasticsearch

Published: September 28, 2021 Updated: October 19, 2022

Security Bulletin ID SB2021092812
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper Preservation of Permissions (CVE-ID: CVE-2021-22137)

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to search queries do not properly preserve security permissions when executing certain cross-cluster search queries. A remote user can disclose existence of documents via search functionality, when Document or Field Level Security is used.


2) Security restrictions bypass (CVE-ID: CVE-2021-22135)

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. A remote user can perform certain queries to enable the profiler and suggester on index and disclose existence of documents and fields.


Remediation

Install update from vendor's website.