First published: Mon Apr 02 2018(Updated: )
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.3.0 | |
IBM QRadar Security Information and Event Manager | =7.3.1 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p1 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1733 is considered to have a medium severity level due to the potential exposure of sensitive information in log files.
To fix CVE-2017-1733, ensure you apply the latest patches provided by IBM for QRadar versions 7.3.0 and 7.3.1.
Users of IBM QRadar versions 7.3.0 and 7.3.1, including specific patch levels, are affected by CVE-2017-1733.
CVE-2017-1733 can expose potentially sensitive information contained in log files.
Yes, local users can exploit CVE-2017-1733 to access sensitive information if the logs are not secured.