SB2024020514 - Missing authorization in IBM Instana Observability 



SB2024020514 - Missing authorization in IBM Instana Observability

Published: February 5, 2024

Security Bulletin ID SB2024020514
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing Authorization (CVE-ID: CVE-2023-33246)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authorization in several components of RocketMQ, including NameServer, Broker, and Controller. A remote non-authenticated attacker can use the update configuration function to execute arbitrary commands on the system. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.


Remediation

Install update from vendor's website.