First published: Fri Jan 13 2023(Updated: )
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.4.0 | |
IBM QRadar Security Information and Event Manager | =7.5.0 | |
Linux Linux kernel | ||
IBM QRadar SIEM | <=7.4 | |
IBM QRadar SIEM | <=7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identifier for IBM QRadar SIEM is CVE-2023-22875.
The severity of CVE-2023-22875 is high with a CVSS score of 8.4.
CVE-2023-22875 allows for the copying of certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key.
IBM QRadar SIEM versions 7.4.0 and 7.5.0 are affected by CVE-2023-22875.
You can find more information about CVE-2023-22875 on the IBM X-Force Exchange website and the IBM support pages.