Lucene search

K
ibmIBMC9857D4F6A62A55DDA788B0BCC7C4CA31999B536BE3EDCB5E8F152A721C2C056
HistoryMar 04, 2021 - 10:25 p.m.

Security Bulletin: Google-api-client as used by IBM QRadar SIEM is vulnerable to authorization bypass (CVE-2020-7692)

2021-03-0422:25:03
www.ibm.com
13

0.007 Low

EPSS

Percentile

79.8%

Summary

Google-api-client as used by IBM QRadar SIEM is vulnerable to authorization bypass, caused by no PKCE support implemented.

Vulnerability Details

CVEID:CVE-2020-7692
**DESCRIPTION:**Google APIs google-oauth-java-client could allow a remote attacker to bypass security restrictions, caused by no PKCE support implemented. By executing a specially-crafted application, an attacker could exploit this vulnerability to obtain the authorization code, and gain authorization to the protected resource.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/184858 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

7.3

All GoogleCommon versions before 7.3.0-QRADAR-PROTOCOL-GoogleCommon-7.3-20210126200436

7.4

All GoogleCommon versions before 7.4.0-QRADAR-PROTOCOL-GoogleCommon-7.4-20210126200430

Remediation/Fixes

7.3

7.3.0-QRADAR-PROTOCOL-GoogleCommon-7.3-20210126200436

7.4

7.4.0-QRADAR-PROTOCOL-GoogleCommon-7.4-20210126200430

Workarounds and Mitigations

None

0.007 Low

EPSS

Percentile

79.8%

Related for C9857D4F6A62A55DDA788B0BCC7C4CA31999B536BE3EDCB5E8F152A721C2C056