CVE-2023-47146: IBM QRadar SIEM information disclosure
Published Dec 19, 2023
·Updated
IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372.
Affected Software
8 affected components
IBM QRadar Security Information and Event Manager=7.5.0
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_1
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_2
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_3
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_4
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_5
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_6
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_7
Remediation
Patch Available
Event History
Dec 19, 2023
CVE Published
10:04 PM
Data Sourced
10:04 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47146?
CVE-2023-47146 has a moderate severity allowing privileged users to access sensitive information.
2
How do I fix CVE-2023-47146?
To fix CVE-2023-47146, apply the latest updates and patches provided by IBM for QRadar SIEM 7.5.
3
Who is affected by CVE-2023-47146?
CVE-2023-47146 affects IBM QRadar Security Information and Event Manager version 7.5.0 and its update packs.
4
What type of information can be exposed due to CVE-2023-47146?
CVE-2023-47146 may expose sensitive domain information to a privileged user due to misidentified data.
5
Is there a workaround for CVE-2023-47146?
Currently, there are no established workarounds for CVE-2023-47146 aside from applying the recommended updates.