IBM QRadar’s Major Flaws Allow Remote Execution of Unauthorized Code

IBM has recently released a security advisory detailing several vulnerabilities within its QRadar Suite Software. These issues span multiple components and have been addressed in the newest software update.

The IBM QRadar Suite Software is a robust cybersecurity solution that merges Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), network traffic analysis, and vulnerability management into a single platform for threat detection, incident response, and compliance management. The software, alongside IBM Cloud Pak for Security, has been identified with several exploitable vulnerabilities.

Affected Versions:

  • IBM Cloud Pak for Security: Versions 1.10.0.0 to 1.10.11.0
  • QRadar Suite Software: Versions 1.10.12.0 to 1.10.23.0

Recent CVE Reports:

  • CVE-2024-28799: IBM QRadar Suite Software (1.10.12.0 to 1.10.23.0) and IBM Cloud Pak for Security (1.10.0.0 to 1.10.11.0) reveal sensitive data improperly during backend processes. More details — CVE (@CVEnew) August 14, 2024

Key Vulnerabilities Identified:

  1. Node.js jose Module (CVE-2024-28176): Flaw during JWE Decryption operations could be exploited to cause a denial of service by overwhelming CPU or memory resources.
  2. Jinja Cross-Site Scripting (CVE-2024-34064): Vulnerability in the Jinja template engine allows injection of malicious attributes into web pages, which may lead to theft of authentication credentials.
  3. idna Module Denial of Service (CVE-2024-3651): A specially crafted argument can be used by local users to cause a denial of service by depleting system resources.
  4. Plaintext Credential Storage (CVE-2024-25024): User credentials are stored in plaintext within QRadar Suite, risking unauthorized access by local users.
  5. gRPC on Node.js Denial of Service (CVE-2024-37168): Fault in memory allocation within gRPC on Node.js can be exploited to induce a denial of service through specially crafted messages.
  6. Node.js undici Information Disclosure (CVE-2024-30260): Mismanagement of Authorization headers by the undici module can expose sensitive information, potentially leading to further attacks.
  7. Node.js undici Security Bypass (CVE-2024-30261): Security restrictions can be bypassed due to a flaw in the fetch integrity option, allowing tampered requests to be accepted.
  8. Improper Data Display (CVE-2024-28799): QRadar Suite Software reveals sensitive data during backend operations, resulting in unintended disclosure.
  9. Arbitrary Code Execution in fast-loops (CVE-2024-39008): A vulnerability in robinweser’s fast-loops allows for remote code execution through prototype pollution, posing risks of arbitrary code execution or denial of service.
  10. Node.js ip Module SSRF (CVE-2024-29415): Vulnerability in the ip module facilitates server-side request forgery due to improper IP address handling.

Recommended Actions:

IBM urges users to upgrade to version 1.10.24.0 or newer to address these vulnerabilities. Detailed upgrade instructions are available [here].

Currently, there are no available workarounds or mitigations, so users should apply the updates without delay.

More Articles & Posts