QID 375723
Date Published: 2021-10-05
QID 375723: IBM QRadar SIEM Insecure Deserialization Vulnerability (6409306)
IBM QRadar is an enterprise security information and event management product. It collects log data from an enterprise, its network devices, host assets and operating systems, applications, vulnerabilities, and user activities and behaviors.
IBM QRadar could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Affected Versions:
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 7
QID Detection Logic:
It checks for vulnerable versions of IBM QRadar.
Remote attacker could execute arbitrary commands on the system
QRadar / QRM / QVM / QRIF / QNI 7.4.2 Patch 2
QRadar / QRM / QVM / QRIF / QNI 7.3.3 Patch 7 IF 1
- 6409306 -
www.ibm.com/support/pages/node/6409306
CVEs related to QID 375723
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6409306 |
|