VDB
BDU%3A2022-03778
BDU%3A2022-03778
PUBLISHED
CVSS 9 CRITICAL
Уязвимость диспетчера сообщений Apache Kafka, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти ограничения безопасности
Risk Scores
CVSS 2.0
9
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., Apache Software Foundation, IBM Corp. | Primavera Unifier, Primavera P6 Enterprise Project Portfolio Management, Kafka, IBM QRadar SIEM |
Timeline
- Jun 27, 2022 CVE Published
References
- https://www.ibm.com/blogs/psirt/security-bulletin-apache-kafka-as-used-by-ibm-qradar-siem-is-vulnerable-to-information-disclosure-cve-2021-38153-cve-2018-17196/ url
- https://bugzilla.redhat.com/show_bug.cgi?id=1732309 url
- https://access.redhat.com/security/cve/cve-2018-17196 url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://www.oracle.com/security-alerts/cpuoct2020.html url
- http://www.securityfocus.com/bid/109139 url
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/d1581fb6464c9bec8a72575c01f5097d68e2fbb230aff24622622a58@%3Ccommits.kafka.apache.org%3E url
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E url
- https://lists.apache.org/thread.html/r66de86b9a608c1da70b2d27d765c11ec88edf6e5dd6f379ab33e072a@%3Cuser.flink.apache.org%3E url
- https://lists.apache.org/thread.html/r8890b8f18f1de821595792b58b968a89692a255bc20d86d395270740@%3Ccommits.druid.apache.org%3E url
- https://lists.apache.org/thread.html/rc27d424d0bdeaf31081c3e246db3c66e882243ae3f342dfa845e0261@%3Ccommits.kafka.apache.org%3E url
- https://www.mail-archive.com/dev@kafka.apache.org/msg99277.html advisory