PT-2024-6128 · Ibm · Ibm Qradar Suite+1

Published

2024-08-14

·

Updated

2024-09-21

·

CVE-2024-28799

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM QRadar Suite Software versions 1.10.12.0 through 1.10.23.0 IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0
Description The issue is related to the improper display of sensitive data during back-end commands, potentially resulting in the unexpected disclosure of this information to a local privileged user in non-default configurations. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For IBM QRadar Suite Software versions 1.10.12.0 through 1.10.23.0, upgrade to a version that properly handles sensitive data during back-end commands. For IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0, upgrade to a version that properly handles sensitive data during back-end commands. As a temporary workaround, consider restricting access to back-end commands to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-07044
CVE-2024-28799

Affected Products

Ibm Cloud Pak For Security
Ibm Qradar Suite