Lucene search

K
ibmIBM66E7870E2D6A7BF69EDFF2995796310CA34301279563212952F92DEB6D26363F
HistoryMar 05, 2019 - 6:25 p.m.

Security Bulletin: IBM QRadar SIEM is vulnerable to publicly disclosed vulnerability from GNU glibc (CVE-2018-11237)

2019-03-0518:25:02
www.ibm.com
14

0.001 Low

EPSS

Percentile

22.9%

Summary

Publicly disclosed vulnerability from GNU glibc

Vulnerability Details

CVEID: CVE-2018-11237
**Description:**GNU glibc is vulnerable to a buffer overflow, caused by improper bounds of checking by the mempcpy function. By sending a specially-crafted request, a remote attacker could overflow a buffer and execute arbitrary code on the system.
**CVSS Base Score:**7.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/143580&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products and Versions

  • IBM QRadar SIEM 7.3.0 - 7.3.1 Patch 7

Remediation/Fixes

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm security qradar siemeq7.3