CVE-2014-4832: Infoleak
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4832?
CVE-2014-4832 has a medium severity as it allows remote attackers to intercept sensitive cookie information.
How do I fix CVE-2014-4832?
To fix CVE-2014-4832, upgrade to IBM QRadar SIEM and Risk Manager versions 7.1 MR2 Patch 9 or 7.2 Patch 1 and later.
Which IBM products are affected by CVE-2014-4832?
CVE-2014-4832 affects IBM Security QRadar SIEM, QRadar Risk Manager, and QRadar Vulnerability Manager versions prior to certain patch levels.
What type of attack is related to CVE-2014-4832?
CVE-2014-4832 is related to network sniffing attacks, where an attacker can capture sensitive information over HTTP.
Is CVE-2014-4832 specific to a particular version of QRadar?
Yes, CVE-2014-4832 specifically affects QRadar versions 7.1 prior to MR2 Patch 9 and 7.2 prior to Patch 1.