CERT-In Vulnerability Note
CIVN-2023-0397
Multiple Vulnerabilities in IBM QRadar SIEM
Original Issue Date:December 29, 2023
Severity Rating: CRITICAL
Software Affected
- IBM QRadar SIEM version 7.5 - 7.5.0 UP7
Overview
Multiple vulnerabilities have been reported in the IBM QRadar SIEM components which could be exploited by an attacker to obtain sensitive information, bypass security restrictions, gain elevated privileges, cause denial of service condition or conduct cross site scripting, phishing & SSRF attacks on the targeted system.
Description
These vulnerabilities exist due to flaw in Eclipse Jetty, Linux Kernel, Apache Tomcat, Apache ActiveMQ and ActiveMQ Legacy OpenWire Module, VMware Tanzu Spring for Apache Kafka and Apache Struts components of IBM QRadar SIEM. An attacker could exploit these vulnerabilities by sending a specially crafted request.
Successful exploitation of these vulnerabilities could allow an attacker to obtain sensitive information, bypass security restrictions, gain elevated privileges, cause denial of service condition or conduct cross site scripting, phishing & SSRF attacks on the targeted system.
Solution
Apply appropriate fix/patches as mentioned:
https://www.ibm.com/support/pages/node/7099297
Vendor Information
IBM
https://www.ibm.com/support/pages/node/7099297
References
IBM
https://www.ibm.com/support/pages/node/7099297
CVE Name
CVE-2023-41080
CVE-2023-40787
CVE-2023-46589
CVE-2023-47146
CVE-2023-36478
CVE-2023-41835
CVE-2023-22049
CVE-2023-22045
CVE-2023-34040
CVE-2023-46604
CVE-2023-45648
CVE-2023-42795
CVE-2023-44487
CVE-2023-35001
CVE-2023-32233
CVE-2023-36479
CVE-2023-40167
CVE-2023-26049
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|