CVE-2019-4264: Medium severity ibm qradar security information and event manager vulnerability
Published May 29, 2019
·Updated
IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.
Affected Software
4 affected components
IBM QRadar Security Information and Event Manager>=7.1.2<7.2.8
IBM QRadar Security Information and Event Manager=7.2.8
IBM QRadar Security Information and Event Manager=7.2.8-p1
IBM QRadar Security Information and Event Manager=7.2.8-p2
Remediation
Patch Available
Event History
May 29, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4264?
CVE-2019-4264 is classified as a vulnerability that can lead to sensitive information leakage due to improper certificate validation.
2
How do I fix CVE-2019-4264?
To resolve CVE-2019-4264, update IBM QRadar SIEM to a version that addresses the certificate validation issue.
3
Who is affected by CVE-2019-4264?
Organizations using IBM QRadar SIEM versions 7.2.8 or earlier are affected by CVE-2019-4264.
4
What kind of attack can exploit CVE-2019-4264?
CVE-2019-4264 can be exploited via man-in-the-middle attacks that spoof trusted entities.
5
When was CVE-2019-4264 published?
CVE-2019-4264 was published in 2019, detailing vulnerabilities in IBM QRadar SIEM.