IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.
An attacker with administrative privileges in the IBM QRadar SIEM system can modify configuration files responsible for the automatic update mechanism. Through this manipulation, it is possible to substitute or upload a malicious autoupdate file, which is then executed by the system with elevated privileges. The vulnerability is classified as CWE-73 (External Control of File Name or Path), which means that the application does not sufficiently verify the paths or file names specified by user-controlled data.
An attacker can execute arbitrary system commands on the IBM QRadar SIEM server, which in practice means complete takeover of the system, violation of data confidentiality, and compromising the integrity and availability of the entire SIEM platform.
Apply patches available from the vendor according to the references (https://www.ibm.com/support/pages/node/7237317). Additionally, it is recommended to restrict administrative access to the IBM QRadar system only to trusted accounts and monitor changes to configuration files of the update mechanism.
IBM QRadar SIEM in versions 7.5 through 7.5.0 Update Package 12 inclusive.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HIBM Qradar Security Information And Event Manager
APPIbm7.5.0Linux Kernel
OSLinuxall versions
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
RCE przez YAML deserialization w IBM Aspera Faspex
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
Command Injection w VMware Workspace One Access i Identity Manager