CVE-2014-0837: Medium severity IBM QRadar Security Information and Event Manager vulnerability
The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0837?
CVE-2014-0837 is considered a critical vulnerability due to the potential for man-in-the-middle attacks against affected systems.
How do I fix CVE-2014-0837?
To fix CVE-2014-0837, upgrade to IBM Security QRadar SIEM version 7.2.1 or later, which includes the necessary security enhancements.
What versions are affected by CVE-2014-0837?
CVE-2014-0837 affects IBM Security QRadar SIEM version 7.2 MR1 and earlier.
What type of attack does CVE-2014-0837 allow?
CVE-2014-0837 allows attackers to perform man-in-the-middle attacks by spoofing servers with crafted certificates.
Is CVE-2014-0837 related to SSL security?
Yes, CVE-2014-0837 is related to SSL security as it involves the mishandling of X.509 certificate verification during the AutoUpdate process.