First published: Thu Jan 09 2020(Updated: )
IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.3.0<=7.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4508 has a high severity due to the potential for local attackers to decrypt weakly stored credentials.
To fix CVE-2019-4508, upgrade IBM QRadar SIEM to a version that resolves the weak credential storage issue.
CVE-2019-4508 affects IBM QRadar SIEM versions 7.3.0 through 7.3.3.
The potential risks include unauthorized access to sensitive information due to local attackers being able to decrypt stored credentials.
Yes, CVE-2019-4508 specifically impacts the IBM QRadar Security Information and Event Manager.