First published: Wed Jul 24 2024(Updated: )
IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM X-Force ID: 272201.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite Software | <=1.10.12.0 - 1.10.22.0 | |
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.11.0 | |
IBM QRadar Suite | >=1.10.12.0<1.10.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47728 is considered a medium severity vulnerability due to potential exposure of sensitive information.
To fix CVE-2023-47728, upgrade IBM QRadar Suite Software to versions 1.10.23.0 or higher and IBM Cloud Pak for Security to versions 1.10.12.0 or higher.
CVE-2023-47728 affects users of IBM QRadar Suite Software versions 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
CVE-2023-47728 is classified as an information disclosure vulnerability.
Yes, CVE-2023-47728 can be exploited remotely by an attacker if the conditions are met.