Lucene search

K
ibmIBMEC2B1E711297BF805445F74A427E645AD13280B474A3848A55AC2ADEA3DA45CD
HistoryJul 25, 2018 - 2:29 p.m.

Security Bulletin: IBM QRadar Network Security is affected by an OpenSSH vulnerability

2018-07-2514:29:31
www.ibm.com
17

0.007 Low

EPSS

Percentile

79.7%

Summary

IBM QRadar Network Security has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2017-15906
**DESCRIPTION:*OpenSSH is vulnerable to a denial of service, caused by an error in the process_open() function when in read-only mode. A remote authenticated attacker could exploit this vulnerability to create zero-length files and cause a denial of service.
CVSS Base Score: 6.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/133128&gt; for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM QRadar Network Security 5.4.0

Remediation/Fixes

Product

|

VRMF

|

Remediation/First Fix

—|—|—

IBM QRadar Network Security

| 5.4.0 |

Install Firmware 5.4.0.5 from the Available Updates page of the Local Management Interface, or by performing a One Time Scheduled Installation from SiteProtector.

Or

Download Firmware 5.4.0.5 from IBM Security License Key and Download Center and upload and install via the Available Updates page of the Local Management Interface.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm qradar network securityeq5.4.0