CVE-2018-1650
published 2018-12-05CVE-2018-1650: IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force…
PriorityP426medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.34%
26.5th percentile
IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | qradar_incident_forensics | — | — |
| ibm | qradar_incident_forensics | — | — |
| ibm | qradar_incident_forensics | >= 7.2.0 < 7.2.8 | 7.2.8 |
| ibm | qradar_incident_forensics | >= 7.3.0 < 7.3.1 | 7.3.1 |
| ibm | qradar_siem | — | — |
| ibm | qradar_siem | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19477 ghostscript: access bypass in psi/zfjbig2.c (700168)
bugzilla·2018-11-28·CVSS 7.8
CVE-2018-19477 [HIGH] CVE-2018-19477 ghostscript: access bypass in psi/zfjbig2.c (700168)
CVE-2018-19477 ghostscript: access bypass in psi/zfjbig2.c (700168)
A vulnerability was found in Artifex Ghostscript before 9.26. A JBIG2Decode type confusion in psi/zfjbig2.c allows remote attackers to bypass intended access restrictions.
References:
https://bugs.ghostscript.com/show_bug.cgi?id=700168
https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26
Upstream Patches:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ef252e7dc214bcbd9a2539216aab9202848602bb
http://git.ghostscript.com/?p=ghostpdl.git;h=606a22e77e7f081781e99e44644cd0119f559e03
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1654470]
---
Mitigation:
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-1650
Bugzilla
CVE-2018-14656 kernel: Arbitrary Kernel Read into dmesg via Missing Address Check in segfault Handler
bugzilla·2018-09-17·CVSS 7.0
CVE-2018-14656 [HIGH] CVE-2018-14656 kernel: Arbitrary Kernel Read into dmesg via Missing Address Check in segfault Handler
CVE-2018-14656 kernel: Arbitrary Kernel Read into dmesg via Missing Address Check in segfault Handler
A missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel memory at an arbitrary kernel address into the dmesg log.
References:
https://bugs.chromium.org/p/project-zero/issues/detail?id=1650
https://lore.kernel.org/lkml/[email protected]/T/
https://seclists.org/oss-sec/2018/q4/9
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=342db04ae71273322f0011384a9ed414df8bdae4
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1629942]
---
This is fixed for Fedora with the 4.18.6 stable updates.
---
External References:
http
2018-12-05
Published