PT-2024-5151 · Ibm · Ibm Qradar Software Suite+1

Ben Goodspeed

+8

·

Published

2024-06-27

·

Updated

2024-08-01

·

CVE-2022-38383

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0 IBM QRadar Software Suite versions 1.10.12.0 through 1.10.21.0
Description: The issue is related to the storage of protected information in an unencrypted form, allowing an attacker to gain unauthorized access to sensitive data. This can occur because web pages are stored locally and can be read by another user on the system.
Recommendations: For IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0, consider restricting access to sensitive web pages to minimize the risk of exploitation. For IBM QRadar Software Suite versions 1.10.12.0 through 1.10.21.0, consider implementing additional security measures to protect stored information, such as encryption or access controls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-05698
CVE-2022-38383

Affected Products

Ibm Cloud Pak For Security
Ibm Qradar Software Suite