PT-2021-13894 · Ibm · Ibm Qradar Siem

Published

2021-07-26

·

Updated

2022-07-12

·

CVE-2021-20337

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM QRadar SIEM versions 7.3.0 through 7.3.3 Patch 8 IBM QRadar SIEM versions 7.4.0 through 7.4.3 GA
Description: The issue is related to the use of weaker than expected cryptographic algorithms, which could allow an attacker to decrypt highly sensitive information.
Recommendations: For IBM QRadar SIEM versions 7.3.0 through 7.3.3 Patch 8, update to a version that uses stronger cryptographic algorithms. For IBM QRadar SIEM versions 7.4.0 through 7.4.3 GA, update to a version that uses stronger cryptographic algorithms. As a temporary workaround, consider restricting access to sensitive information until a patch is available.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20337

Affected Products

Ibm Qradar Siem