First published: Fri Feb 16 2024(Updated: )
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite Software | <=1.10.12.0 - 1.10.17.0 | |
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.11.0 | |
IBM QRadar Suite | >=1.10.12.0<1.10.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22337 has a medium severity rating due to the potential exposure of sensitive information stored in log files.
To fix CVE-2024-22337, implement recommended security practices to restrict access to log files and apply patches from IBM for the affected versions.
CVE-2024-22337 affects IBM QRadar Suite versions 1.10.12.0 to 1.10.17.0 and IBM Cloud Pak for Security versions 1.10.0.0 to 1.10.11.0.
CVE-2024-22337 could expose potentially sensitive information logged by the IBM QRadar Suite and Cloud Pak for Security.
Yes, local users could potentially exploit CVE-2024-22337 to read sensitive information from accessible log files.