Lucene search

K
ibmIBMF1833E6F9BE51F0AE92E1A4D7A4A70D19D539BA964236451CCAD9F68AC5701E0
HistoryJun 29, 2023 - 3:05 p.m.

Security Bulletin: Google OAuth Client Library for Java as used by IBM QRadar SIEM is vulnerable to verification bypass (CVE-2021-22573)

2023-06-2915:05:06
www.ibm.com
11
ibm qradar siem
google oauth client library
verification bypass
cve-2021-22573
remote attacker
token signatures
security restrictions
version 7.5.0
version 7.4.0
remediation fix

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

8.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

0.001 Low

EPSS

Percentile

23.8%

Summary

Google OAuth Client Library for Java as used by IBM QRadar SIEM is vulnerable to verification bypass. IBM QRadar SIEM has addressed the applicable vulnerability.

Vulnerability Details

CVEID:CVE-2021-22573
**DESCRIPTION:**Google OAuth Client Library for Java could allow a remote attacker to bypass security restrictions, caused by improper verification of token signatures. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass verification on the client side.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/226003 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM QRadar SIEM All GoogleCommon versions before 7.5.0-QRADAR-PROTOCOL-GoogleCommon-7.5-20230310180259.noarch.rpm
IBM QRadar SIEM All GoogleCommon versions before 7.4.0-QRADAR-PROTOCOL-GoogleCommon-7.4-20230310180308.noarch.rpm

Remediation/Fixes

Product Version Remediation/First Fix
IBM QRadar SIEM 7.5.0 7.5.0-QRADAR-PROTOCOL-GoogleCommon-7.5-20230310180259.noarch.rpm
IBM QRadar SIEM 7.4.0 7.4.0-QRADAR-PROTOCOL-GoogleCommon-7.4-20230310180308.noarch.rpm

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_qradar_siemMatch7.5
OR
ibmibm_qradar_siemMatch7.5

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

8.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

0.001 Low

EPSS

Percentile

23.8%

Related for F1833E6F9BE51F0AE92E1A4D7A4A70D19D539BA964236451CCAD9F68AC5701E0