CVE-2024-22336: IBM QRadar Suite information disclosure
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279976.
Other sources
IBM QRadar Suite stores potentially sensitive information in log files that could be read by a local user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22336?
CVE-2024-22336 has a moderate severity level due to its potential exposure of sensitive information.
How do I fix CVE-2024-22336?
To mitigate CVE-2024-22336, ensure that log files containing sensitive information are secured and access is restricted to authorized users only.
Which versions are affected by CVE-2024-22336?
CVE-2024-22336 affects IBM QRadar Suite versions 1.10.12.0 to 1.10.17.0 and IBM Cloud Pak for Security versions 1.10.0.0 to 1.10.11.0.
Does CVE-2024-22336 allow local user exploitation?
Yes, CVE-2024-22336 could potentially allow a local user to read sensitive information stored in log files.
Is there an exploit available for CVE-2024-22336?
While there is no known public exploit, the vulnerability's nature could allow for local information disclosure if exploited.