CVE-2024-45636
EUVD-2024-5561911.06.2026, 16:16
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_edr | 3.12 ≤ 𝑥 < 3.12.25 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-256 - Plaintext Storage of a PasswordStoring a password in plaintext may result in a system compromise.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.