CVE-2023-22875: IBM Security QRadar SIEM information disclosure
IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.
Other sources
IBM QRadar SIEM copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not required that key.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability identifier for IBM QRadar SIEM?
The vulnerability identifier for IBM QRadar SIEM is CVE-2023-22875.
What is the severity of CVE-2023-22875?
The severity of CVE-2023-22875 is high with a CVSS score of 8.4.
How does CVE-2023-22875 affect IBM QRadar SIEM?
CVE-2023-22875 allows for the copying of certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key.
Which versions of IBM QRadar SIEM are affected by CVE-2023-22875?
IBM QRadar SIEM versions 7.4.0 and 7.5.0 are affected by CVE-2023-22875.
How can I find more information about CVE-2023-22875?
You can find more information about CVE-2023-22875 on the IBM X-Force Exchange website and the IBM support pages.