First published: Wed Mar 01 2017(Updated: )
IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.2.5 | |
IBM QRadar Security Information and Event Manager | =7.2.6 | |
IBM QRadar Security Information and Event Manager | =7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2880 describes a security flaw in IBM QRadar 7.2 that allows a local user to access the stored encryption key for the service account password.
The affected versions of IBM QRadar for CVE-2016-2880 include 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, and 7.2.7.
CVE-2016-2880 is classified as a medium severity vulnerability.
To mitigate the risk of CVE-2016-2880, it is recommended to update IBM QRadar to the latest version to ensure the encryption of sensitive information is secure.
CVE-2016-2880 can be exploited by any local user who has access to the system on which the affected IBM QRadar versions are installed.