CVE-2024-31905

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.  IBM X-Force ID:  289858.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
ibmCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
ibmqradar_network_packet_capture
7.5.0
ibmqradar_network_packet_capture
7.5.0:update_package_1
ibmqradar_network_packet_capture
7.5.0:update_package_2
ibmqradar_network_packet_capture
7.5.0:update_package_3
ibmqradar_network_packet_capture
7.5.0:update_package_4
ibmqradar_network_packet_capture
7.5.0:update_package_5
ibmqradar_network_packet_capture
7.5.0:update_package_6
ibmqradar_network_packet_capture
7.5.0:update_package_7
𝑥
= Vulnerable software versions