CVE-2022-34351
17.02.2023, 19:15
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | qradar_security_information_and_event_manager | 7.4.0 ≤ 𝑥 < 7.4.3 |
ibm | qradar_security_information_and_event_manager | 7.4.3 |
ibm | qradar_security_information_and_event_manager | 7.4.3:fix_pack_1 |
ibm | qradar_security_information_and_event_manager | 7.4.3:fix_pack_2 |
ibm | qradar_security_information_and_event_manager | 7.4.3:fix_pack_3 |
ibm | qradar_security_information_and_event_manager | 7.4.3:fix_pack_4 |
ibm | qradar_security_information_and_event_manager | 7.4.3:fix_pack_5 |
ibm | qradar_security_information_and_event_manager | 7.4.3:fix_pack_6 |
ibm | qradar_security_information_and_event_manager | 7.4.3:fix_pack_7 |
ibm | qradar_security_information_and_event_manager | 7.5.0 |
ibm | qradar_security_information_and_event_manager | 7.5.0:update_pack_1 |
ibm | qradar_security_information_and_event_manager | 7.5.0:update_pack_2 |
ibm | qradar_security_information_and_event_manager | 7.5.0:update_pack_3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.