CVE-2018-1418
published 2018-04-26CVE-2018-1418: IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
PriorityP273high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
52.07%
98.8th percentile
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | >= 7.2.0 < 7.2.8 | 7.2.8 |
| ibm | security_qradar_siem | — | — |
| ibm | security_qradar_siem | — | — |
| msrc | azl3_patch_2.7.6-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_patch_2.7.6-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_patch_2.7.6-7_on_cbl_mariner_1.0 | — | — |
| msrc | patch-2.7.6-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | patch-2.7.6-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | patch-2.7.6-7.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | patch-2.7.6-7.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | patch-2.7.6-9.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | patch-2.7.6-9.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
| msrc | patch-debuginfo-2.7.6-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | patch-debuginfo-2.7.6-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | patch-debuginfo-2.7.6-7.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | patch-debuginfo-2.7.6-7.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated POST requests to /ForensicsAnalysisServlet/ with query parameter action=setSecurityTokens — this is the authentication bypass (stage 1) of the exploit chain. ↗
- →Alert on HTTP 403 responses from /ForensicsAnalysisServlet/ — the Metasploit module uses this as a positive detection signal that the target is vulnerable. ↗
- →Monitor for new or modified files written under /store/configservices/staging/updates/ by the 'nobody' user — this is where the stage-2 payload is written for subsequent root execution. ↗
- →Watch for outbound netcat reverse-shell connections spawned by QRadar processes, particularly /usr/bin/nc -e /bin/sh, which is the stage-2 reverse shell command. ↗
- →The exploit chain requires three CVEs chained together (CVE-2016-9722, CVE-2018-1418, CVE-2018-1612); correlate alerts across all three for high-confidence detection. ↗
- →The Forensics web application code is present and exploitable even when the feature is disabled (e.g., QRadar Community Edition) — do not rely on feature-disable as a mitigation for detection scoping. ↗
- ·Vulnerable version scope is confirmed by IBM: QRadar 7.2.x up to 7.2.8 patch 12 and 7.3.x up to 7.3.1 patch 3. ↗
- ·The Metasploit module only supports generic/shell_reverse_tcp due to payload constraints imposed by the exploit chain. ↗
- ·Stage 3 root execution relies on a QRadar scheduled task; the attacker must wait up to ~80 seconds after stage 2 for the root shell to arrive. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v6h4-975x-x7vq: IBM Security QRadar SIEM 7
ghsa_unreviewed·2022-05-14
CVE-2018-1418 [HIGH] CWE-287 GHSA-v6h4-975x-x7vq: IBM Security QRadar SIEM 7
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
Microsoft
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear t
vendor_msrc·2018-04-10·CVSS 7.8
CVE-2018-1000156 [HIGH] CWE-20 GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear t
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed
Red Hat
patch: Malicious patch files cause ed to execute arbitrary commands
vendor_redhat·2018-04-05·CVSS 7.8
CVE-2018-1000156 [HIGH] CWE-77 patch: Malicious patch files cause ed to execute arbitrary commands
patch: Malicious patch files cause ed to execute arbitrary commands
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
Package: patch (Red Hat Enterprise Linux 5) - Will not fix
Package: patch (Red Hat Enterprise Linux 8) - Not affected
No detection rules found.
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
exploitdb·2018-07-11
CVE-2018-1612 IBM QRadar SIEM - Remote Code Execution (Metasploit)
IBM QRadar SIEM - Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'securerandom'
class MetasploitModule 'IBM QRadar SIEM Unauthenticated Remote Code Execution',
'Description' => %q{
IBM QRadar SIEM has three vulnerabilities in the Forensics web application
that when chained together allow an attacker to achieve unauthenticated remote code execution.
The first stage bypasses authentication by fixating session cookies.
The second stage uses those authenticated sessions cookies to write a file to disk and execute
that file as the "nobody" user.
The third and final stage occurs when the file executed as "nobody" writes an entry into the
database that cau
Metasploit
IBM QRadar SIEM Unauthenticated Remote Code Execution
metasploit
IBM QRadar SIEM Unauthenticated Remote Code Execution
IBM QRadar SIEM Unauthenticated Remote Code Execution
IBM QRadar SIEM has three vulnerabilities in the Forensics web application that when chained together allow an attacker to achieve unauthenticated remote code execution. The first stage bypasses authentication by fixating session cookies. The second stage uses those authenticated sessions cookies to write a file to disk and execute that file as the "nobody" user. The third and final stage occurs when the file executed as "nobody" writes an entry into the database that causes QRadar to execute a shell script controlled by the attacker as root within the next minute. Details about these vulnerabilities can be found in the advisories listed in References. The Forensics web application is disabled in QRadar Community Edition, but the code
No writeups or analysis indexed.
http://www.ibm.com/support/docview.wss?uid=swg22015797https://exchange.xforce.ibmcloud.com/vulnerabilities/138824https://www.exploit-db.com/exploits/45005/http://www.ibm.com/support/docview.wss?uid=swg22015797https://exchange.xforce.ibmcloud.com/vulnerabilities/138824https://www.exploit-db.com/exploits/45005/
2018-04-26
Published