First published: Fri Feb 16 2024(Updated: )
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279975.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite Software | <=1.10.12.0 - 1.10.17.0 | |
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.11.0 | |
IBM QRadar Suite | >=1.10.12.0<1.10.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-22335 is considered moderate due to the exposure of potentially sensitive information in log files.
To fix CVE-2024-22335, upgrade IBM QRadar Suite to version 1.10.18.0 or later and IBM Cloud Pak for Security to version 1.10.12.0 or later.
CVE-2024-22335 affects IBM QRadar Suite versions 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
CVE-2024-22335 exposes potentially sensitive information that is stored in log files accessible to local users.
Using affected versions of IBM QRadar Suite or Cloud Pak for Security while CVE-2024-22335 is unpatched poses a risk of local users accessing sensitive log information.