• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – SamSam Ransomware launches cyber-attacks worldwide
December 4, 2018
Rewterz Threat Advisory – SplitSpectre, a new Spectre-like CPU attack
December 5, 2018

Rewterz Threat Advisory – CVE-2018-1730 & CVE-2017-1622 – IBM QRadar Risk Manager / SIEM / Incident Forensics Multiple Vulnerabilities

December 4, 2018

Multiple vulnerabilities in IBM QRadar Risk Manager, SIEM and Incident Forensics may lead to Denial of Service, Exposure of sensitive information and Spoofing.

 

 

IMPACT:  NORMAL

 

 

PUBLISH DATE:  04-Dec-2018

 

 

OVERVIEW

 

 

IBM QRadar Risk Manager, IBM QRadar SIEM, and IBM QRadar Incident Forensics are found to contain vulnerabilities which can be exploited by malicious people to conduct spoofing attacks, disclose sensitive information, and cause a DoS (Denial of Service).

 

 

ANALYSIS

 

 

While parsing XML entities, an error occurs which can be exploited to disclose otherwise restricted information. It may also induce a Denial of Service condition via a specially crafted XML document that includes external entity references.

 

 

A Man-in-the-Middle (MitM) attack can be launched by exploiting an error that occurs while handling certificates. This way, an attacker may proceed to conduct successful spoofing attacks.

 

 

The vulnerabilities are reported in versions 7.2.0 through 7.2.8 Patch 13.

 

 

AFFECTED PRODUCTS

 

 

  • IBM Security QRadar SIEM 7.x
  • IBM Security QRadar Incident Forensics 7.2.x
  • IBM Security QRadar Risk Manager 7.x

 

 

UPDATES

 

 

Update affected versions to version 7.2.8 Patch 14.

 

 

If you think you’re the victim of a cyber-attack, immediately send an email to soc@rewterz.com.

  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.