News: 1587495888

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

IBM == Insecure Business Machines: No-auth remote root exec exploit in Data Risk Manager drops after Big Blue snubs bug report

(2020/04/21)


IBM has acknowledged that it mishandled a bug report that identified four vulnerabilities in its enterprise security software, and plans to issue an advisory.

[1]IBM Data Risk Manager offers security-focused vulnerability scanning and analytics, to help businesses identify weaknesses in their infrastructure. At least some versions of the Linux-powered suite included four exploitable holes, identified and, at first, privately disclosed by security researcher Pedro Ribeiro at no charge. Three are considered to be critical, and one is high risk.

The software flaws can be chained together to achieve unauthenticated remote code execution as root on a vulnerable installation, as described in [2]an advisory Ribeiro published today on GitHub.

Prior to going public, Ribeiro had tried to get CC/CERT to privately coordinate responsible disclosure with IBM, but Big Blue refused to accept the bug report. He said the mainframe giant replied thus: "We have assessed this report and closed as being out of scope for our vulnerability disclosure program since this product is only for 'enhanced' support paid for by our customers."

"This is an unbelievable response by IBM, a multi-billion dollar company that is selling security enterprise products and security consultancy to huge corporations worldwide," said Ribeiro in his disclosure.

Bad cup of Java leaves nasty taste in IBM Watson's 'AI' mouth: Five security bugs to splat in analytics gear [3]READ MORE

The vulnerabilities consist of authentication bypass, command injection, insecure default password, and arbitrary file download. Using the first three, an unauthenticated remote user can run arbitrary code, and there's now [4]a Metasploit module to do so. Vulnerabilities one and four allow an unauthenticated attacker to download arbitrary files from the system. There's also a Metasploit module [5]for that attack chain .

The flaws don't yet have CVE designations, and as far as we can tell, no patches nor updates to address the holes are available right now. The first three have been confirmed to affect IBM Data Risk Manager 2.0.1 to 2.0.3. Ribeiro believes versions 2.0.4 to 2.0.6, the latest release, are also vulnerable but that has not been confirmed. The fourth affects IDRM 2.0.2 and 2.0.3, and possibly 2.0.4 to 2.0.6. The Register asked IBM whether 2.0.6 is affected but IBM's spokesperson did not respond.

IBM however did say that it had fumbled the report. "A process error resulted in an improper response to the researcher who reported this situation to IBM," a company spokesperson told The Register . "We have been working on mitigation steps and they will be discussed in a security advisory to be issued."

Ribeiro dismissed IBM's response in an email to The Register . "Well, what can I say," he said. "It's a joke right? I think it's pretty sad that I have to disclose a zero-day and shame them publicly to get them to patch critical vulnerabilities in a security product, while they sell themselves as an elite company providing security services."

"Like I said in my advisory, I was just looking to disclose it to them without asking anything in return except a mention when the vulnerability was fixed. Having said that, I also think it's pretty sad that a multi-billion dollar company like IBM can't scrounge a few dollars to pay security researchers despite being part of HackerOne."

As Riberio observed in his advisory, IBM's [6]vulnerability reward program offers [7]no cash awards , only kudos. ®

Sponsored: [8]How To Accelerate Brilliant Digital Experiences With Low-Code



[1] https://www.ibm.com/products/data-risk-manager

[2] https://github.com/pedrib/PoC/blob/master/advisories/IBM/ibm_drm/ibm_drm_rce.md

[3] https://www.theregister.co.uk/2019/03/18/java_watson_flaws/

[4] https://github.com/rapid7/metasploit-framework/pull/13300

[5] https://github.com/rapid7/metasploit-framework/pull/13301

[6] https://hackerone.com/ibm

[7] https://www.ibm.com/security/secure-engineering/report.html

[8] https://go.theregister.co.uk/tl/1936/-8552/how-to-accelerate-brilliant-digital-experiences-with-low-code?td=wptl1936

And thus is why hackers profit...

Shadow Systems

You take an honest researcher attempting to Do The Right Thing by telling the company first about security flaws in their product. Company makes oodles & oodles of money but can't be arsed to give any of that dosh to the folks trying to help them help themselves. Honest researcher gets an offer from dishonest hacker to pay money for undisclosed flaws. Now honest researcher has a choice: keep trying to DTRT with a company that snubs them, refuses to pay them, and at best might mention their name in some later patch, or a quick buck right now from someone that is delighted by said researcher's work. It doesn't take a rocket surgeon to figure out where that situation is headed...

Re: And thus is why hackers profit...

rcxb

Crime is always more profitable in the short-term, but tends to be a bad career choice over the long-term. Until very recently, NOBODY paid bug bounties, and It's still debatable whether they are making things safer or not.

Ask yourself why blood and organ donations don't net the donor a nice big check.

Re: And thus is why hackers profit...

Blackjack

I would comment on several people who got away with crime for a long time and either died without being caught or got a slap on the wrist but since this is not not an article about economics I will just name one.

Julio Humberto Grondona (September 18, 1931 – July 30, 2014) died without getting caught.

Hackerone is part of the problem

Detective Emil

Search "hackerone perverse incentive" or similar.

Doctor Syntax

It might be an unbelievable response from a multi-billion dollar company but it's a totally believable one form a company that has been systemically hollowed out by getting rid of its experienced, expensive staff.

Anonymous Coward

"Having said that, I also think it's pretty sad that a multi-billion dollar company like IBM can't scrounge a few dollars to pay security researchers despite being part of HackerOne."

Meh. They won't scrounge enough dollars to retain experienced staff either. But if you're one of those at the top, they always seem to find some money somewhere.....

(Never thought I'd be telling Malcolm and Ilya the same thing... :-)
-- Larry Wall in <199711071819.KAA29909@wall.org>