CVE-2015-2016
published 2015-10-04CVE-2015-2016: Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary…
PriorityP352critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.13%
79.8th percentile
Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unknown vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qx6g-6438-72hc: Unspecified vulnerability in IBM QRadar SIEM 7
ghsa_unreviewed·2022-05-17
CVE-2015-2016 [HIGH] GHSA-qx6g-6438-72hc: Unspecified vulnerability in IBM QRadar SIEM 7
Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unknown vectors.
GHSA
Spoofing attack due to unvalidated KDC in node-krb5
ghsa·2020-09-01
CVE-2016-1000238 [MEDIUM] Spoofing attack due to unvalidated KDC in node-krb5
Spoofing attack due to unvalidated KDC in node-krb5
Affected versions of `node-krb5` do not validate the KDC prior to authenticating, which might allow an attacker with network access and enough time to spoof the KDC and impersonate a valid user without knowing their credentials.
## Recommendation
It appears that this will remain unfixed indefinitely, as the Github issue for this vulnerability has been open since 2015, with no work on it since then.
At this time, the best available mitigation is to use an alternative module that is actively maintained and provides similar functionality. There are [multiple modules fitting this criteria available on npm.](https://www.npmjs.com/search?q=kerberos).
Red Hat
salt: local_batch client external authentication not respected
vendor_redhat·2017-01-20·CVSS 8.8
CVE-2017-5192 [HIGH] salt: local_batch client external authentication not respected
salt: local_batch client external authentication not respected
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.
Statement: This issue did not affect the versions of the salt as shipped with Red Hat Ceph Storage 1.3, Red Hat Ceph Storage 2, and Red Hat Storage Console 2 as salt-api and salt-ssh are not shipped with these products.
Mitigation: Disable salt-api for mitigation.
Package: salt (Red Hat Ceph Storage 1.3) - Not affected
Package: salt (Red Hat Ceph Storage 2) - Not affected
Package: salt (Red Hat Storage Console 2) - Not affected
Red Hat
php: Use After Free in unserialize()
vendor_redhat·2016-12-08·CVSS 9.8
CVE-2016-9936 [CRITICAL] CWE-416 php: Use After Free in unserialize()
php: Use After Free in unserialize()
The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6834.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Will not fix
Package: php (Red Hat OpenShift Enterprise 2) - Will not fix
Package: rh-php56-php (Red Hat Software Collections) - Will not fix
VMware
VMware ESXi, Fusion, Player, and Workstation updates address important guest privilege escalation vulnerability
vendor_vmware·2016-01-07·CVSS 6.3
CVE-2015-6933 [MEDIUM] VMware ESXi, Fusion, Player, and Workstation updates address important guest privilege escalation vulnerability
VMSA-2016-0001: VMware ESXi, Fusion, Player, and Workstation updates address important guest privilege escalation vulnerability
Important Windows-based guest privilege escalation in VMware Tools A kernel memory corruption vulnerability is present in the VMware Tools "Shared Folders" (HGFS) feature running on Microsoft Windows. Successful exploitation of this issue could lead to an escalation of privilege in the guest operating system. VMware would like to thank Dmitry Janushkevich from the Secunia Research Team for reporting this issue to us. Note: This vulnerability does not allow for privilege escalation from the guest operating system to the host. Host memory can not be manipulated from the guest operating system by exploiting this flaw. The Common Vulnerabilities and Exposures project
No detection rules found.
Exploit-DB
glibc - 'getaddrinfo' Remote Stack Buffer Overflow
exploitdb·2016-09-06·CVSS 8.1
CVE-2015-7547 [HIGH] glibc - 'getaddrinfo' Remote Stack Buffer Overflow
glibc - 'getaddrinfo' Remote Stack Buffer Overflow
---
/*
add by SpeeDr00t@Blackfalcon (jang kyoung chip)
This is a published vulnerability by google in the past.
Please refer to the link below.
Reference:
- https://googleonlinesecurity.blogspot.kr/2016/02/cve-2015-7547-glibc-getaddrinfo-stack.html
- https://github.com/fjserna/CVE-2015-7547
- CVE-2015-7547: glibc getaddrinfo stack-based buffer overflow
When Google announced about this code(vulnerability),
it was missing information on shellcode.
So, I tried to completed the shellcode.
In the future, I hope to help your study.
(gdb) r
Starting program: /home/haker/client1
Got object file from memory but can't read symbols: File truncated.
[UDP] Total Data len recv 36
[UDP] Total Data len recv 36
udp send
sendto 1
TCP Connected with
Exploit-DB
DropBearSSHD 2015.71 - Command Injection
exploitdb·2016-03-03·CVSS 6.4
CVE-2016-3116 [MEDIUM] DropBearSSHD 2015.71 - Command Injection
DropBearSSHD 2015.71 - Command Injection
---
VuNote
Author:
Ref: https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-3116
Version: 0.2
Date: Mar 3rd, 2016
Tag: dropbearsshd xauth command injection may lead to forced-command bypass
Overview
Name: dropbear
Vendor: Matt Johnston
References: * https://matt.ucc.asn.au/dropbear/dropbear.html [1]
Version: 2015.71
Latest Version: 2015.71
Other Versions: Dropbear is a relatively small SSH server and client. It runs on a variety of POSIX-based platforms. Dropbear is open source software, distributed under a MIT-style license. Dropbear is particularly useful for "embedded"-type Linux (or other Unix) systems, such as wireless routers.
Summary
An authenticated user may inject arbitrary xauth commands by sending an
x11 channel request th
Bugzilla
CVE-2016-4472 expat: Undefined behavior and pointer overflows
bugzilla·2016-06-09·CVSS 6.8
CVE-2016-4472 [MEDIUM] CVE-2016-4472 expat: Undefined behavior and pointer overflows
CVE-2016-4472 expat: Undefined behavior and pointer overflows
It was found that original patch for issues CVE-2015-1283 and CVE-2015-2716 used overflow checks that could be optimized out by some compilers applying certain optimization settings, which can cause the vulnerability to remain even after applying the patch.
One pattern in the fix for CVE-2015-1283/CVE-2015-2716 is:
/* bufferSize is positive here */
do {
bufferSize *= 2;
} while (bufferSize 0);
if (bufferSize 0 as always true when the execution is defined, and bufferSize 0 out of the loop, that is, compile the code as if it had been written:
if (bufferSize <= 0)
errorCode = XML_ERROR_NO_MEMORY;
return NULL;
else {
do {
bufferSize *= 2;
} while (bufferSize < neededSize);
}
Both cases leads to not eliminating the vulnerability
Bugzilla
CVE-2016-1181 struts: Vulnerability in ActionForm allows unintended remote operations against components on server memory
bugzilla·2016-06-07·CVSS 7.5
CVE-2016-1181 [HIGH] CVE-2016-1181 struts: Vulnerability in ActionForm allows unintended remote operations against components on server memory
CVE-2016-1181 struts: Vulnerability in ActionForm allows unintended remote operations against components on server memory
A vulnerability in Apache Struts 1 ActionForm allowing unintended remote operations against components on server memory, such as Servlets and ClassLoader, was found.
Affects Apache Struts versions 1.0 through 1.3.10
External References:
https://jvn.jp/en/jp/JVN03188560/
Discussion:
Created struts tracking bugs for this issue:
Affects: fedora-all [bug 1343541]
Affects: epel-7 [bug 1343542]
---
Seem a duplicate of CVE-2015-0899. Already fixed
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-0899
---
Patch:
https://github.com/kawasima/struts1-forever/commit/eda3a79907ed8fcb0387a0496d0cb14332f250e8
---
struts-1.3.10-18.fc23 has been pushed to the Fedora 23
Bugzilla
CVE-2015-7579 rubygem-rails-html-sanitizer: XSS vulnerability in Action View's strip_tags function
bugzilla·2016-01-26·CVSS 6.1
CVE-2015-7579 [MEDIUM] CVE-2015-7579 rubygem-rails-html-sanitizer: XSS vulnerability in Action View's strip_tags function
CVE-2015-7579 rubygem-rails-html-sanitizer: XSS vulnerability in Action View's strip_tags function
XSS vulnerability in `Rails::Html::FullSanitizer` used by Action View's `strip_tags` was reported. Due to the way that `Rails::Html::FullSanitizer` is implemented, if an attacker passes an already escaped HTML entity to the input of Action View's `strip_tags` these entities will be unescaped what may cause a XSS attack if used in combination with `raw` or `html_safe`.
External References:
https://groups.google.com/forum/#!msg/rubyonrails-security/OU9ugTZcbjc/PjEP46pbFQAJ
http://weblog.rubyonrails.org/2016/1/25/Rails-5-0-0-beta1-1-4-2-5-1-4-1-14-1-3-2-22-1-and-rails-html-sanitizer-1-0-3-have-been-released/
Discussion:
Created rubygem-rails-html-sanitizer tracking bugs for this issue:
Aff
Bugzilla
CVE-2015-8778 glibc: Integer overflow in hcreate and hcreate_r
bugzilla·2016-01-20·CVSS 9.8
CVE-2015-8778 [CRITICAL] CVE-2015-8778 glibc: Integer overflow in hcreate and hcreate_r
CVE-2015-8778 glibc: Integer overflow in hcreate and hcreate_r
An integer overflow vulnerability was found in hcreate and hcreate_r which can result in an out-of-bound memory access. This could lead to application crashes or, potentially, arbitrary code execution.
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=18240
CVE assignment:
http://seclists.org/oss-sec/2016/q1/153
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1300304]
---
Mitigation:
Do not use any applications which call hcreate or hcreate_r with a large size argument.
These functions are used only rarely, and most callers supply a constant argument. Other applications calculate the size argument in such a way that the error condition cannot be triggered.
---
This issu
Bugzilla
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
bugzilla·2015-12-28·CVSS 5.5
CVE-2015-8665 [MEDIUM] CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c
An Out-of-bounds read flaw was found in libtiff. An attacker could create a specially-crafted TIFF file, which could cause libtiff to crash.
Reference:
http://www.openwall.com/lists/oss-security/2015/12/24/4
Discussion:
Please inform me when you will have a patch or at least a reference for the bugzilla.
Greetings
Petr
---
Patch for this and bug#1294427:
https://github.com/vadz/libtiff/commit/f94a29a822f5528d2334592760fbb7938f15eb55
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1547 https://rhn.redhat.com/errata/RHSA-2016-1547.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1546 https://rhn.redhat.com/
Bugzilla
CVE-2015-5323 jenkins: API tokens of other users available to admins (SECURITY-200)
bugzilla·2015-11-16·CVSS 6.5
CVE-2015-5323 [MEDIUM] CVE-2015-5323 jenkins: API tokens of other users available to admins (SECURITY-200)
CVE-2015-5323 jenkins: API tokens of other users available to admins (SECURITY-200)
The following flaw was found in Jenkins:
API tokens of other users were exposed to admins by default. On instances that don't implicitly grant RunScripts permission to admins, this allowed admins to run scripts with another user's credentials.
In very specific circumstances, it allows admins to gain permissions they would not otherwise have.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Discussion:
Fixed in Fedora in:
jenkins-1.609.3-3.fc22
jenkins-1.625.2-2.fc23
jenkins-1.625.2-2.fc24
---
This issue has been addressed in the following products:
RHEL 7 Version of OpenShift Enterprise 3.1
Via RHSA-2016:0070 https://access.redhat.com/errata/
Fortinet
Zimbra Collaboration XSS Vulnerability: Be Careful If You're Using Zimbra Email
blogs_fortinet·2016-01-31·CVSS 6.1
CVE-2015-7609 [MEDIUM] Zimbra Collaboration XSS Vulnerability: Be Careful If You're Using Zimbra Email
FORTIGUARD LABS THREAT RESEARCH
Zimbra Collaboration XSS Vulnerability: Be Careful If You're Using Zimbra Email
By Peixue Li | January 31, 2016
Summary
Recently Zimbra released Zimbra Collaboration 8.6 Patch 5. It fixed 2 Cross-Site Scripting (XSS) vulnerabilities which were discovered and reported by security researcher of Fortinet's FortiGuard labs in October 2015. CVE-2015-7609 was assigned to identify these 2 XSS vulnerabilities. One of them is caused due to insufficiently sanitizing the content of email message body. It allows remote attackers to launch XSS attack against Zimbra Collaboration users by simply sending a specially-crafted email. In this blog, we want to elaborate this vulnerability.
Proof of Concept
To reproduce this vulnerability, we can use any email service to cr
Unit42
NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
blogs_unit42·2016-01-21·CVSS 8.8
[HIGH] NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
## NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
Vicky Ray
Robert Falcone
Published: January 21, 2016
Malware
Threat Research
NetTraveler
Spear Phishing
Trojan
Ufa
Ufe
Uzbekistan
Unit 42 recently identified a targeted attack against an individual working for the Foreign Ministry of Uzbekistan in China. A spear-phishing email was sent to a diplomat of the Embassy of Uzbekistan who is likely based in Beijing, China. In this report, we’ll review how the actors attempted to exploit CVE-2012-0158 to install the NetTraveler Trojan.
On December 12, 2015, a spear-phishing email was sent to a diplomat of the Embassy of Uzbekistan. The body and subject of the email suggests that the email was spoofed to look like it was sent by the Russian Foreign Ministry and the att
2015-10-04
Published