Lucene search

K
ibmIBM775BC3D6188444CAC857A13E72F698DF7AB39820633466FC356F934DFCE15A13
HistorySep 26, 2022 - 5:45 a.m.

Security Bulletin: IBM QRadar SIEM can be affected by a command injection vulnerability (CVE-2013-2970)

2022-09-2605:45:55
www.ibm.com
12
ibm qradar siem
command injection
vulnerability
remote shell access
cve-2013-2970

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.003

Percentile

69.1%

Abstract

A vulnerability has been discovered within the IBM QRadar Security Information and Event Manager (SIEM) software that allows an authenticated user to execute limited operating system commands on the QRadar device and gain limited remote shell access.

Content

VULNERABILITY DETAILS:

DESCRIPTION:

CVE-2013-2970
A command injection vulnerability has been discovered within the IBM QRadar SIEM software that allows an authenticated user to execute operating system commands as a limited access user on the QRadar device. This access could be used to gain remote shell access as that webservices user. Even though authenticated users of the QRadar SIEM do not necessarily have shell access, action should be taken to ensure this issue is patched as soon as possible.

The attack can be conducted over the internet. Some degree of specialized knowledge and techniques are required to conduct this attack. Multiple authentication attempts are required for this attack. An exploit may have a limited impact on the confidentiality of information and the integrity of data and could reduce performance / cause interruptions to availability.

CVEID:
CVE-2013-2970

CVSS Base Score: 6.0
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/83872&gt;
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:P/I:P/A:P)

AFFECTED PRODUCTS AND VERSIONS:
IBM QRadar Security Information and Event Manager (SIEM) 7.0
IBM QRadar Security Information and Event Manager (SIEM) 7.1

REMEDIATION:

The vulnerability is fixed in the following version of QRadar SIEM:

Workaround(s):
None

Mitigation(s):
None

REFERENCES:
ยท Complete CVSS Guide
ยท On-line Calculator V2_ _
ยท CVE-2013-2970
ยท https://exchange.xforce.ibmcloud.com/vulnerabilities/83872
ยท IBM Security Alerts
ยท QRadar SIEM 7.1MR2 Patch 1
ยท Interim Fix 7.0.0-QRadar-QRSCRIPT-CVE-2013-2970.sh

RELATED INFORMATION:
_IBM Secure Engineering Web Portal _
IBM Product Security Incident Response Blog

ACKNOWLEDGEMENT
This vulnerability was reported to IBM by Stephen Hosom

_*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash. _

_Note: _According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an โ€œindustry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.โ€ IBM PROVIDES THE CVSS SCORES โ€œAS ISโ€ WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

[{โ€œProductโ€:{โ€œcodeโ€:โ€œSSBQACโ€,โ€œlabelโ€:โ€œIBM Security QRadar SIEMโ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU059โ€,โ€œlabelโ€:โ€œIBM Software w/o TPSโ€},โ€œComponentโ€:โ€œNot Applicableโ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œPF016โ€,โ€œlabelโ€:โ€œLinuxโ€}],โ€œVersionโ€:โ€œ7.1;7.0โ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB24โ€,โ€œlabelโ€:โ€œSecurity Softwareโ€}}]

Affected configurations

Vulners
Node
ibmqradar_network_securityMatch7.1
OR
ibmqradar_network_securityMatch7.0
VendorProductVersionCPE
ibmqradar_network_security7.1cpe:2.3:a:ibm:qradar_network_security:7.1:*:*:*:*:*:*:*
ibmqradar_network_security7.0cpe:2.3:a:ibm:qradar_network_security:7.0:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.003

Percentile

69.1%

Related for 775BC3D6188444CAC857A13E72F698DF7AB39820633466FC356F934DFCE15A13