PT-2023-8377 · Ibm · Ibm Qradar Siem
CVE-2023-43041
·
Publicado
2023-10-29
·
Atualizado
2023-11-07
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM QRadar SIEM version 7.5
Description
The issue is related to the lack of protection for service data in the IBM QRadar SIEM system, which can be exploited by a remote attacker to disclose protected information. Specifically, a delegated Admin tenant user with a specific domain security profile assigned can see data from other domains due to an incomplete fix.
Recommendations
For IBM QRadar SIEM version 7.5, apply the fix provided by IBM to address the incomplete fix for the previous issue, ensuring that delegated Admin tenant users cannot access data from other domains.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Qradar Siem