CVE-2019-4508: High severity ibm qradar security information and event manager vulnerability
IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.
Other sources
IBM QRadar SIEM uses weak credential storage in some instances which could be decrypted by a local attacker.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4508?
CVE-2019-4508 has a high severity due to the potential for local attackers to decrypt weakly stored credentials.
How do I fix CVE-2019-4508?
To fix CVE-2019-4508, upgrade IBM QRadar SIEM to a version that resolves the weak credential storage issue.
Which versions of IBM QRadar SIEM are affected by CVE-2019-4508?
CVE-2019-4508 affects IBM QRadar SIEM versions 7.3.0 through 7.3.3.
What are the potential risks associated with CVE-2019-4508?
The potential risks include unauthorized access to sensitive information due to local attackers being able to decrypt stored credentials.
Is CVE-2019-4508 specific to any IBM products?
Yes, CVE-2019-4508 specifically impacts the IBM QRadar Security Information and Event Manager.