Lucene search

K
ibmIBM8C0C5ACA41EFEC61398DC20968E73A34DEA2F276BF484D1FE1231AE746A10916
HistoryJun 16, 2018 - 9:39 p.m.

Security Bulletin: OpenSSL as used in IBM QRadar SIEM is vulnerable to a Denial of Service attack, and Sensitive Information Exposure. (CVE-2015-3194, CVE-2015-3195, CVE-2015-3196)

2018-06-1621:39:34
www.ibm.com
6

0.953 High

EPSS

Percentile

99.4%

Summary

OpenSSL vulnerabilities announced 12-3-15 this will also cover Node.js which consumes OpenSSL

Vulnerability Details

CVE-ID: CVE-2015-3194 **
Description:OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference when verifying certificates via a malformed routine. An attacker could exploit this vulnerability using signature verification routines with an absent PSS parameter to cause any certificate verification operation to crash. **
CVSS Base Score:
5.3**
CVSS Temporal Score:** See https://exchange.xforce.ibmcloud.com/vulnerabilities/108503 for the current score**
CVSS Environmental Score:** Undefined*
CVSS Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

**
CVE-ID:CVE-2015-3195 **
Description:OpenSSL could allow a remote attacker to obtain sensitive information, caused by a memory leak in a malformed X509_ATTRIBUTE structure. An attacker could exploit this vulnerability to obtain CMS data and other sensitive information. **
CVSS Base Score:
5.3

CVSS Temporal Score:** See https://exchange.xforce.ibmcloud.com/vulnerabilities/108504 for the current score**
CVSS Environmental Score:** Undefined*
CVSS Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

**
CVE-ID:CVE-2015-3196 **
Description:OpenSSL is vulnerable to a denial of service, caused by a race condition when PSK identity hints are received by a multi-threaded client and the SSL_CTX structure is updated with the incorrect value. An attacker could exploit this vulnerability to possibly corrupt memory and cause a denial of service. **
CVSS Base Score:
3.7

CVSS Temporal Score:** See https://exchange.xforce.ibmcloud.com/vulnerabilities/108505 for the current score**
CVSS Environmental Score:** Undefined*
CVSS Vector:** CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products and Versions

· IBM QRadar SIEM and QRadar Incident Forensics 7.2.n

· IBM QRadar SIEM 7.1.n

Remediation/Fixes

· IBM QRadar/QRM/QVM/QRIF 7.2.6 Patch 2

· IBM QRadar 7.1 MR2 Patch 12 Interim Fix 1

Workarounds and Mitigations

None