Multiple IBM QRadar Products CVE-2014-4832 Information Disclosure Vulnerability
BID:71347
Info
Multiple IBM QRadar Products CVE-2014-4832 Information Disclosure Vulnerability
| Bugtraq ID: | 71347 |
| Class: | Design Error |
| CVE: |
CVE-2014-4832 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2014 12:00AM |
| Updated: | Nov 25 2014 12:00AM |
| Credit: | Paul Ionescu, Brennan Brazeau, John Zuccato, Jonathan Fitz-Gerald, and Warren Moynihan. |
| Vulnerable: |
IBM QRadar Vulnerability Manager 7.2.3 Patch 4 IBM QRadar Vulnerability Manager 7.2.3 IBM QRadar Vulnerability Manager 7.2 IBM QRadar Vulnerability Manager 7.2 MR2 IBM QRadar Security Information and Event Manager 7.2.3 Patch 4 IBM QRadar Security Information and Event Manager 7.2.0 IBM QRadar Security Information and Event Manager 7.2 MR3 IBM QRadar Security Information and Event Manager 7.2 MR2 IBM QRadar Security Information and Event Manager 7.2 IBM QRadar Security Information and Event Manager 7.1MR2 Patch 1 IBM QRadar Security Information and Event Manager 7.1 MR2 Patch 8 IBM QRadar Security Information and Event Manager 7.1 MR2 IBM QRadar Security Information and Event Manager 7.1 IBM QRadar Risk Manager 7.2.3 Patch 4 IBM QRadar Risk Manager 7.2.3 IBM QRadar Risk Manager 7.2 MR2 IBM QRadar Risk Manager 7.1MR2 Patch 1 IBM QRadar Risk Manager 7.1 MR2 Patch 8 IBM QRadar Risk Manager 7.1 MR2 IBM QRadar Risk Manager 7.1 |
| Not Vulnerable: |
IBM QRadar Security Information and Event Manager 7.2.4 Patch 1 IBM QRadar Security Information and Event Manager 7.1 MR2 Patch 9 |
Discussion
Multiple IBM QRadar Products CVE-2014-4832 Information Disclosure Vulnerability
Multiple IBM QRadar Products are prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to the application credentials by sniffing network traffic through a man-in-the-middle attack. Successful exploits will lead to other attacks.
The following product versions are affected:
IBM QRadar Security Information and Event Manager 7.2.3 Patch 4 and prior
IBM QRadar Security Information and Event Manager 7.1 MR2 Patch 8 and prior
IBM QRadar Vulnerability Manager 7.2.3 Patch 4 and prior
IBM QRadar Risk Manager 7.2.3 Patch 4 and prior
IBM QRadar Risk Manager 7.1 MR2 Patch 8 and prior
Multiple IBM QRadar Products are prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to the application credentials by sniffing network traffic through a man-in-the-middle attack. Successful exploits will lead to other attacks.
The following product versions are affected:
IBM QRadar Security Information and Event Manager 7.2.3 Patch 4 and prior
IBM QRadar Security Information and Event Manager 7.1 MR2 Patch 8 and prior
IBM QRadar Vulnerability Manager 7.2.3 Patch 4 and prior
IBM QRadar Risk Manager 7.2.3 Patch 4 and prior
IBM QRadar Risk Manager 7.1 MR2 Patch 8 and prior
Solution / Fix
Multiple IBM QRadar Products CVE-2014-4832 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple IBM QRadar Products CVE-2014-4832 Information Disclosure Vulnerability
References:
References: