First published: Thu Aug 12 2021(Updated: )
IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain. IBM X-Force ID: 206979.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.4.3 | |
IBM QRadar Security Information and Event Manager | =7.4.3-fix_pack_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-29880.
The severity of CVE-2021-29880 is medium with a CVSS score of 6.5.
IBM QRadar SIEM versions 7.4.3 and 7.4.3 Fix Pack 1 are affected by CVE-2021-29880.
CVE-2021-29880 could allow information disclosure between tenants in IBM QRadar SIEM when using domains or multi-tenancy.
Yes, IBM has released a fix for CVE-2021-29880. Please refer to IBM's support page for more information.