First published: Wed Oct 07 2020(Updated: )
IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.3.0<=7.3.3 | |
IBM QRadar Security Information and Event Manager | >=7.4.0<=7.4.1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p2 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p4 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4545 is a vulnerability in IBM QRadar SIEM when configured to use Active Directory Authentication that may be susceptible to spoofing attacks.
The severity of CVE-2019-4545 is high with a severity value of 7.5.
IBM QRadar SIEM versions 7.3.0 to 7.3.3-p4 and versions 7.4.0 to 7.4.1 are affected by CVE-2019-4545.
To mitigate the vulnerability in IBM QRadar SIEM, update to a version higher than 7.4.1 or apply the latest available patch for versions 7.3.0 to 7.3.3-p4.
More information about CVE-2019-4545 can be found in the IBM X-Force ID: 165877 and on the IBM support page.