First published: Fri Nov 28 2014(Updated: )
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Risk Manager | =7.1.0 | |
IBM QRadar Risk Manager | =7.2.0 | |
IBM QRadar Risk Manager | =7.2.1 | |
IBM QRadar Risk Manager | =7.2.2 | |
IBM QRadar Risk Manager | =7.2.3 | |
IBM QRadar Risk Manager | =7.2.4 | |
IBM QRadar Vulnerability Manager | =7.2.0 | |
IBM QRadar Vulnerability Manager | =7.2.1 | |
IBM QRadar Vulnerability Manager | =7.2.2 | |
IBM QRadar Vulnerability Manager | =7.2.3 | |
IBM QRadar Vulnerability Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4832 has a medium severity as it allows remote attackers to intercept sensitive cookie information.
To fix CVE-2014-4832, upgrade to IBM QRadar SIEM and Risk Manager versions 7.1 MR2 Patch 9 or 7.2 Patch 1 and later.
CVE-2014-4832 affects IBM Security QRadar SIEM, QRadar Risk Manager, and QRadar Vulnerability Manager versions prior to certain patch levels.
CVE-2014-4832 is related to network sniffing attacks, where an attacker can capture sensitive information over HTTP.
Yes, CVE-2014-4832 specifically affects QRadar versions 7.1 prior to MR2 Patch 9 and 7.2 prior to Patch 1.