CVE-2023-47728: IBM QRadar Suite Software information disclosure
IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM X-Force ID: 272201.
Other sources
IBM QRadar Suite Software could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47728?
CVE-2023-47728 is considered a medium severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2023-47728?
To fix CVE-2023-47728, upgrade IBM QRadar Suite Software to versions 1.10.23.0 or higher and IBM Cloud Pak for Security to versions 1.10.12.0 or higher.
Who is affected by CVE-2023-47728?
CVE-2023-47728 affects users of IBM QRadar Suite Software versions 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
What type of vulnerability is CVE-2023-47728?
CVE-2023-47728 is classified as an information disclosure vulnerability.
Can CVE-2023-47728 be exploited remotely?
Yes, CVE-2023-47728 can be exploited remotely by an attacker if the conditions are met.