=========================================================================== ZMCIRT Vulnerability Bulletin ZMC-2022.21.02.0900 UPDATE IBM QRadar SIEM: CVSS (Max): 6.5 22nd February 2022 =========================================================================== Product: IBM QRadar SIEM Publisher: IBM Operating System: Linux variants Resolution: Patch/Upgrade CVE Names: CVE-2021-3712 Reference: ASB-2022.0043 ASB-2021.0198 Original Bulletin: https://www.ibm.com/support/pages/node/6557430 Comment: CVSS (Max): 6.5 CVE-2021-3712 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L) CVSS Source: IBM Calculator: https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Revision History: February 21 2022: Added CVSS max score February 21 2022: Change in the OS February 21 2022: Initial Release - --------------------------BEGIN INCLUDED TEXT-------------------- OpenSSL as used by IBM QRadar SIEM is vulnerable to information disclosure (CVE-2021-3712) Document Information Document number : 6557430 Modified date : 18 February 2022 Product : IBM QRadar SIEM Software version : 7.3, 7.4 Operating system(s): Linux Summary OpenSSL as used by IBM QRadar SIEM is vulnerable to information disclosure. Vulnerability Details CVEID: CVE-2021-3712 DESCRIPTION: OpenSSL could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read when processing ASN.1 strings. By sending specially crafted data, an attacker could exploit this vulnerability to read contents of memory on the system or perform a denial of service attack. CVSS Base score: 6.5 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/ 208073 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L) Affected Products and Versions IBM QRadar SIEM 7.5.0 GA IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 4 IBM QRadar SIEM 7.3.3 GA - 7.3.3 Fix Pack 10 Remediation/Fixes QRadar / QRM / QVM / QRIF / QNI 7.5.0 Update Pack 1 QRadar / QRM / QVM / QRIF / QNI 7.4.3 Fix Pack 4 Interim Fix 04 QRadar / QRM / QVM / QRIF / QNI 7.3.3 Fix Pack 10 Interim Fix 02 Workarounds and Mitigations None Change History 16 Feb 2022: Initial Publication - --------------------------END INCLUDED TEXT-------------------- ZMCIRT has made every effort to ensure that the informaqtion contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. ZMCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Internet Email: report@cirt.zm Telephone: 7070 ZMCIRT personnel answer during Zambian business hours which are 8am to 5pm. On call after hours for member emergencies only. ===========================================================================
Copyright @2023 ZAMBIA CIRT