First published: Tue Apr 12 2022(Updated: )
IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.3.0<7.3.3 | |
IBM QRadar Security Information and Event Manager | >=7.4.0<7.4.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_2 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_4 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_5 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_6 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_7 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_8 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_9 | |
IBM QRadar Security Information and Event Manager | =7.4.3 | |
IBM QRadar Security Information and Event Manager | =7.4.3-fix_pack_1 | |
IBM QRadar Security Information and Event Manager | =7.4.3-fix_pack_2 | |
IBM QRadar Security Information and Event Manager | =7.4.3-fix_pack_3 | |
IBM QRadar Security Information and Event Manager | =7.5.0 | |
Linux Linux kernel | ||
IBM QRadar SIEM | <=7.5.0 GA | |
IBM QRadar SIEM | <=7.4.3 GA - 7.4.3 FP4 | |
IBM QRadar SIEM | <=7.3.3 GA - 7.3.3 FP10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38874.
The severity of CVE-2021-38874 is medium with a severity value of 4.3.
The vulnerability in IBM QRadar SIEM allows users to access information across tenant and domain boundaries in some situations.
IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10 are affected by CVE-2021-38874.
You can fix CVE-2021-38874 in IBM QRadar SIEM by applying the appropriate patches available from IBM.