Critical vulnerabilities affecting IBM Sterling B2B Integrator, IBM QRadar SIEM and IBM Disconnected Log Collector (CVE-2022-42920, CVE-2023-51385 and CVE-2023-39410)

Published On: Apr 12, 2024 17:31

Advisory No: TZCERT/SA/2024/04/12-2

Source: IBM

Software Affected: IBM Sterling B2B Integrator, IBM QRadar SIEM and IBM Disconnected Log Collector

Overview

Description

Advisory No: TZCERT/SA/2024/04/12-2

Date of First Release: 12th April 2024

Source: IBM

Software Affected: IBM Sterling B2B Integrator, IBM QRadar SIEM and IBM Disconnected Log Collector

Overview:

IBM products are affected by the critical arbitrary command execution. The vulnerabilities may allow an attacker to remote codes on the affected system.

Description:

IBM QRadar SIEM and IBM Disconnected Log Collector running OpenSSH and Apache Avro Java SDK respectively are affected with critical arbitrary code execution vulnerabilities. Also, the IBM Sterling B2B Integrator running Apache Commons BCEL is affected by the out-of-bounds write vulnerability. All these vulnerabilities may be exploited by the attacker using the specially-crafted request to gain control of the affected systems.

Impact:

Successful exploitation of these vulnerabilities may allow the attacker to take control of the affected system.

Solution:

IBM has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.

References:

  1. https://www.ibm.com/support/pages/node/7148158
  2. https://www.ibm.com/support/pages/node/7148094
  3. https://www.ibm.com/support/pages/node/7148147

Impact

Solution

References

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Report Incident