CVE-2024-22335: IBM QRadar Suite information disclosure
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279975.
Other sources
IBM QRadar Suite stores potentially sensitive information in log files that could be read by a local user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22335?
The severity of CVE-2024-22335 is considered moderate due to the exposure of potentially sensitive information in log files.
How do I fix CVE-2024-22335?
To fix CVE-2024-22335, upgrade IBM QRadar Suite to version 1.10.18.0 or later and IBM Cloud Pak for Security to version 1.10.12.0 or later.
Which versions are affected by CVE-2024-22335?
CVE-2024-22335 affects IBM QRadar Suite versions 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
What kind of information is exposed in CVE-2024-22335?
CVE-2024-22335 exposes potentially sensitive information that is stored in log files accessible to local users.
Is it safe to use IBM QRadar Suite or Cloud Pak for Security while CVE-2024-22335 is unpatched?
Using affected versions of IBM QRadar Suite or Cloud Pak for Security while CVE-2024-22335 is unpatched poses a risk of local users accessing sensitive log information.