PT-2023-5198 · Ibm · Ibm Qradar Siem
CVE-2022-34352
·
Publicado
2023-06-27
·
Atualizado
2023-07-05
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM QRadar SIEM version 7.5.0
Description
The issue is related to the exposure of protected information. It allows a remote attacker to gain unauthorized access to sensitive data. Specifically, a delegated Admin tenant user with a specific domain security profile assigned can see data from other domains.
Recommendations
For IBM QRadar SIEM version 7.5.0, consider restricting access to sensitive data and limiting the privileges of delegated Admin tenant users to minimize the risk of exploitation. As a temporary workaround, review and adjust the domain security profiles assigned to users to prevent unauthorized data access.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Qradar Siem