CVE-2021-29880: Medium severity ibm qradar security information and event manager vulnerability
IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain. IBM X-Force ID: 206979.
Other sources
IBM QRadar SIEM when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-29880.
What is the severity of CVE-2021-29880?
The severity of CVE-2021-29880 is medium with a CVSS score of 6.5.
Which IBM QRadar SIEM versions are affected by CVE-2021-29880?
IBM QRadar SIEM versions 7.4.3 and 7.4.3 Fix Pack 1 are affected by CVE-2021-29880.
How does CVE-2021-29880 affect IBM QRadar SIEM?
CVE-2021-29880 could allow information disclosure between tenants in IBM QRadar SIEM when using domains or multi-tenancy.
Is there a fix available for CVE-2021-29880?
Yes, IBM has released a fix for CVE-2021-29880. Please refer to IBM's support page for more information.