Lucene search

K
ibmIBM0E9A4AA745E8DA99E68988A52A69F5E79367E37CC08A08A6C2BB73B338AFB4AD
HistoryJun 16, 2018 - 10:02 p.m.

Security Bulletin: Open Source XStream as used in IBM QRadar SIEM is vulnerable to Denial of Service. (CVE-2017-7957)

2018-06-1622:02:18
www.ibm.com
7

0.793 High

EPSS

Percentile

98.3%

Summary

Open Source XStream is vulnerable to a Denial of Service attack.

Vulnerability Details

CVEID: CVE-2017-7957**
DESCRIPTION:** XStream is vulnerable to a denial of service, caused by the improper handling of attempts to create an instance of the primitive type โ€˜voidโ€™ during unmarshalling. A remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/125800 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

ยท IBM QRadar SIEM 7.2.0 โ€“ 7.2.8 Patch 8

ยท IBM QRadar SIEM 7.3.0 โ€“ 7.3.0 Patch 3

Remediation/Fixes

ยท QRadar/QRM/QVM/QRIF/QNI 7.2.8 Patch 9

ยท QRadar/QRM/QVM/QRIF/QNI 7.3.0 Patch 4

Workarounds and Mitigations

None

0.793 High

EPSS

Percentile

98.3%

Related for 0E9A4AA745E8DA99E68988A52A69F5E79367E37CC08A08A6C2BB73B338AFB4AD