PT-2023-8377 · Ibm · Ibm Qradar Siem
Published
2023-10-29
·
Updated
2023-11-07
·
CVE-2023-43041
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM QRadar SIEM version 7.5
Description
The issue is related to the lack of protection for service data in the IBM QRadar SIEM system, which can be exploited by a remote attacker to disclose protected information. Specifically, a delegated Admin tenant user with a specific domain security profile assigned can see data from other domains due to an incomplete fix.
Recommendations
For IBM QRadar SIEM version 7.5, apply the fix provided by IBM to address the incomplete fix for the previous issue, ensuring that delegated Admin tenant users cannot access data from other domains.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Qradar Siem