IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  Vunerabilities

    Posted 07/21/20 05:24 AM
    I noticed some new security issues in qradar...
    Cross site scripting and some others
    Security Bulletin: IBM QRadar SIEM is vulnerable to cross-site scripting (CVE-2020-4364)

    solution upgrade to fix pack: 7.3.3-QRADAR-QRSIEM-20200704141002

    However we are on version 7.3.2
    I do not intend to upgrade to 7.3.3 at the moment.

    Will a fixpack for 7.3.2 be released at a later time? 
    or is this version not supported anymore?

    ------------------------------
    Jan Prins
    ------------------------------


  • 2.  RE: Vunerabilities

    Posted 07/21/20 05:46 AM
    Hi Jan,

    Support in 7.3.2 for security patches went EOS in the last few weeks. Only R and R-1 get security fixes.

    The current position is here: https://www.ibm.com/support/pages/node/552703

    The key bit of text is:

    Defect and Security Update Support is available on the current release and its immediate predecessor (that is, R and R-1). If a defect is reported on an earlier release, it must be confirmed to exist in R and R-1 to be logged. All defect corrections and security updates are delivered as a patch update to the most current modification level for that release. NOTE: Only fixes for critical and high severity APARs are delivered in R-1. 

    I would not be expecting a fix-pack and you need to go to R-1 (7.3.3) or R (7.4.0) if this CVE affects your environment.

    Regards,

    ------------------------------
    Darren H.
    ------------------------------



  • 3.  RE: Vunerabilities

    Posted 07/21/20 07:29 AM
    Thanks Darren,

    Subscribed to the update messages to be warned up-front next time.

    Regards,
    Jan

    ------------------------------
    Jan Prins
    ------------------------------