CVE-2018-1612: Infoleak
Published Jul 17, 2018
·Updated
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164.
Affected Software
18 affected components
IBM QRadar Security Information and Event Manager>=7.2.0<=7.2.8
IBM QRadar Security Information and Event Manager=7.2.8-p1
IBM QRadar Security Information and Event Manager=7.2.8-p10
IBM QRadar Security Information and Event Manager=7.2.8-p11
IBM QRadar Security Information and Event Manager=7.2.8-p2
IBM QRadar Security Information and Event Manager=7.2.8-p3
IBM QRadar Security Information and Event Manager=7.2.8-p4
IBM QRadar Security Information and Event Manager=7.2.8-p5
IBM QRadar Security Information and Event Manager=7.2.8-p6
IBM QRadar Security Information and Event Manager=7.2.8-p7
IBM QRadar Security Information and Event Manager=7.2.8-p8
IBM QRadar Security Information and Event Manager=7.2.8-p9
IBM QRadar Security Information and Event Manager=7.3.0
IBM QRadar Security Information and Event Manager=7.3.1
IBM QRadar Security Information and Event Manager=7.3.1-p1
IBM QRadar Security Information and Event Manager=7.3.1-p2
IBM QRadar Security Information and Event Manager=7.3.1-p3
IBM QRadar Security Information and Event Manager=7.3.1-p4
Remediation
Patch Available
Event History
Jul 17, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1612?
CVE-2018-1612 is classified as a high severity vulnerability allowing remote attackers to bypass authentication.
2
How do I fix CVE-2018-1612?
To fix CVE-2018-1612, update your IBM QRadar Incident Forensics software to a version that addresses this vulnerability.
3
Which versions of IBM QRadar are affected by CVE-2018-1612?
IBM QRadar versions 7.2.0 to 7.2.8 and 7.3.0 to 7.3.1 are affected by CVE-2018-1612.
4
Can CVE-2018-1612 lead to information leakage?
Yes, CVE-2018-1612 can allow attackers to obtain sensitive information by bypassing authentication.
5
Is CVE-2018-1612 a local or remote vulnerability?
CVE-2018-1612 is a remote vulnerability that can be exploited over the network by unauthorized attackers.