First published: Wed Jan 17 2024(Updated: )
IBM QRadar could disclose sensitive email information in responses from offense rules.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.5.0 | |
IBM QRadar Security Information and Event Manager | =7.5.0-update_pack_1 | |
IBM QRadar Security Information and Event Manager | =7.5.0-update_pack_2 | |
IBM QRadar Security Information and Event Manager | =7.5.0-update_pack_3 | |
IBM QRadar Security Information and Event Manager | =7.5.0-update_pack_4 | |
IBM QRadar Security Information and Event Manager | =7.5.0-update_pack_5 | |
IBM QRadar Security Information and Event Manager | =7.5.0-update_pack_6 | |
IBM QRadar Security Information and Event Manager | =7.5.0-update_pack_7 | |
IBM QRadar Security Information and Event Manager | <=7.5 - 7.5.0 UP7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-50950 is considered medium, affecting the confidentiality of email information.
To fix CVE-2023-50950, update your IBM QRadar SIEM to the latest release as recommended by IBM.
CVE-2023-50950 affects IBM QRadar SIEM versions from 7.5 through 7.5.0 Update Pack 7.
CVE-2023-50950 can disclose sensitive email information through responses generated by offense rules.
You are vulnerable to CVE-2023-50950 if you are running an affected version of IBM QRadar SIEM up to 7.5.0 Update Pack 7.