Lucene search

K
ibmIBM8003F8575DF3FE34C966814A9556AE2EF8760425073D1AC42A41E2974AA760A5
HistoryJan 11, 2022 - 8:10 p.m.

Security Bulletin: Vulnerability affects IBM Observability with Instana

2022-01-1120:10:06
www.ibm.com
14

0.001 Low

EPSS

Percentile

35.3%

Summary

Vulnerability detected in Elasticsearch before version 7.10.2 affects IBM Observability with Instana

Vulnerability Details

CVEID:CVE-2021-22132
**DESCRIPTION:**Elastic Elasticsearch could allow a remote authenticated attacker to obtain sensitive information, caused by a flaw in the async search API. By reading the .tasks index, an attacker could exploit this vulnerability to obtain sensitive request headers of other users in the cluster.
CVSS Base score: 4.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/194942 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Observability with Instana (OnPrem) All

Remediation/Fixes

Update your existing installation of IBM Observability with Instana as described here: <https://www.instana.com/docs/self_hosted_instana/operations#upgrade-your-container-based-installation&gt;

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm instana observabilityeq209

0.001 Low

EPSS

Percentile

35.3%

Related for 8003F8575DF3FE34C966814A9556AE2EF8760425073D1AC42A41E2974AA760A5