Lucene search

K
ibmIBMA1A641310DC3EC26A5A32A1491C4AE50BBBBBEA686B4FCC9322DE02CB90D7FBA
HistoryFeb 18, 2022 - 1:39 p.m.

Security Bulletin: OpenSSL as used by IBM QRadar SIEM is vulnerable to information disclosure (CVE-2021-3712)

2022-02-1813:39:50
www.ibm.com
39
ibm qradar siem
openssl
information disclosure
cve-2021-3712
vulnerability
remote attack
sensitive information
out-of-bounds read
memory
denial of service
update pack
7.5.0
7.4.3
7.3.3

EPSS

0.005

Percentile

76.3%

Summary

OpenSSL as used by IBM QRadar SIEM is vulnerable to information disclosure.

Vulnerability Details

CVEID:CVE-2021-3712
**DESCRIPTION:**OpenSSL could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read when processing ASN.1 strings. By sending specially crafted data, an attacker could exploit this vulnerability to read contents of memory on the system or perform a denial of service attack.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/208073 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)

Affected Products and Versions

IBM QRadar SIEM 7.5.0 GA

IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 4

IBM QRadar SIEM 7.3.3 GA - 7.3.3 Fix Pack 10

Remediation/Fixes

QRadar / QRM / QVM / QRIF / QNI 7.5.0 Update Pack 1

QRadar / QRM / QVM / QRIF / QNI 7.4.3 Fix Pack 4 Interim Fix 04

QRadar / QRM / QVM / QRIF / QNI 7.3.3 Fix Pack 10 Interim Fix 02

Workarounds and Mitigations

None