CVE-2024-22337: IBM QRadar Suite information disclosure
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.
Other sources
IBM QRadar Suite stores potentially sensitive information in log files that could be read by a local user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22337?
CVE-2024-22337 has a medium severity rating due to the potential exposure of sensitive information stored in log files.
How do I fix CVE-2024-22337?
To fix CVE-2024-22337, implement recommended security practices to restrict access to log files and apply patches from IBM for the affected versions.
Which IBM products are affected by CVE-2024-22337?
CVE-2024-22337 affects IBM QRadar Suite versions 1.10.12.0 to 1.10.17.0 and IBM Cloud Pak for Security versions 1.10.0.0 to 1.10.11.0.
What types of information could be exposed due to CVE-2024-22337?
CVE-2024-22337 could expose potentially sensitive information logged by the IBM QRadar Suite and Cloud Pak for Security.
Can local users exploit CVE-2024-22337?
Yes, local users could potentially exploit CVE-2024-22337 to read sensitive information from accessible log files.