CVE-2023-26276: IBM QRadar information disclosure
Published Jun 22, 2023
·Updated
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147.
Other sources
IBM QRadar uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Affected Software
8 affected components
IBM QRadar Security Information and Event Manager=7.5.0
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_1
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_2
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_3
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_4
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_5
Linux Linux kernel
IBM QRadar SIEM<=7.5.0 - 7.5.0 UP5
Remediation
Patch Available
Event History
Jun 22, 2023
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Jun 27, 2023
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-26276.
2
What software versions are affected by this vulnerability?
IBM QRadar Security Information and Event Manager versions 7.5.0 to 7.5.0 UP5 are affected by this vulnerability.
3
What is the severity of CVE-2023-26276?
The severity of CVE-2023-26276 is high.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by using weaker cryptographic algorithms to decrypt highly sensitive information.
5
Is there a fix available for this vulnerability?
Yes, IBM has provided a fix for this vulnerability. Please refer to the IBM support page for more information.