CVE-2017-1733: Medium severity IBM QRadar Security Information and Event Manager vulnerability
Published Apr 4, 2018
·Updated
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
Affected Software
4 affected components
IBM QRadar Security Information and Event Manager=7.3.0
IBM QRadar Security Information and Event Manager=7.3.1
IBM QRadar Security Information and Event Manager=7.3.1-p1
IBM QRadar Security Information and Event Manager=7.3.1-p2
Remediation
Patch Available
Event History
Apr 4, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1733?
CVE-2017-1733 is considered to have a medium severity level due to the potential exposure of sensitive information in log files.
2
How do I fix CVE-2017-1733?
To fix CVE-2017-1733, ensure you apply the latest patches provided by IBM for QRadar versions 7.3.0 and 7.3.1.
3
Who is affected by CVE-2017-1733?
Users of IBM QRadar versions 7.3.0 and 7.3.1, including specific patch levels, are affected by CVE-2017-1733.
4
What type of information is exposed in CVE-2017-1733?
CVE-2017-1733 can expose potentially sensitive information contained in log files.
5
Can local users exploit CVE-2017-1733?
Yes, local users can exploit CVE-2017-1733 to access sensitive information if the logs are not secured.