PT-2022-15423 · Ibm · Ibm Qradar Siem

Published

2022-07-20

·

Updated

2022-07-26

·

CVE-2022-22424

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM QRadar SIEM versions 7.3 through 7.5
Description The issue allows a local user to obtain sensitive information from the TLS key file due to incorrect file permissions.
Recommendations For versions 7.3 through 7.5, update the file permissions of the TLS key file to prevent unauthorized access. As a temporary workaround, consider restricting access to the TLS key file until a patch is available.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22424

Affected Products

Ibm Qradar Siem