CVE-2023-33859: IBM Security ReaQta information disclosure
Published Jul 8, 2024
·Updated
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.
Other sources
IBM Security ReaQta could disclose sensitive information due to an observable login response discrepancy.
— IBM
Affected Software
2 affected components
IBM Security QRadar EDR<=3.12
IBM Security QRadar EDR=3.12
Event History
Jul 8, 2024
CVE Published
via IBM·12:00 AM
Jul 10, 2024
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-33859?
CVE-2023-33859 has a moderate severity rating due to the potential for sensitive information disclosure.
2
How do I fix CVE-2023-33859?
To address CVE-2023-33859, upgrade IBM Security QRadar EDR to the latest version beyond 3.12.
3
What kind of information could be disclosed by CVE-2023-33859?
CVE-2023-33859 could disclose sensitive information through an observable discrepancy in the login response.
4
Which products are affected by CVE-2023-33859?
CVE-2023-33859 affects IBM Security QRadar EDR version 3.12 and earlier.
5
Who reported CVE-2023-33859?
CVE-2023-33859 was reported by IBM X-Force under the ID 257697.