QID 379090
Date Published: 2023-12-18
QID 379090: IBM QRadar SIEM Multiple Security Vulnerabilities (7070736)
IBM QRadar SIEM copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not required that key.
Affected Versions:
IBM QRadar SIEM 7.5. to 7.5.0 Update Pack 7
QID Detection Logic:
It checks for vulnerable versions of IBM QRadar.
Affected Versions:
IBM QRadar SIEM 7.3.0 to 7.5.0 Update Pack 4 Interim Fix 1
QID Detection Logic:
It checks for vulnerable versions of IBM QRadar.
IBM QRadar SIEM includes vulnerable components (e.g., framework libraries) that may be identified and exploited with automated tools. Additionally, a cross site scripting issue was found.
Solution
The vendor has released patch for the product.
7070736
7070736
Vendor References
- 7070736 -
www.ibm.com/support/pages/node/7070736
CVEs related to QID 379090
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7070736 |
|