First published: Fri Mar 01 2024(Updated: )
IBM CloudPak Bedrock does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite Software | <=1.10.12.0 - 1.10.18.0 | |
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.11.0 | |
IBM QRadar Suite | >=1.10.12.0<=1.10.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-22355 is considered high due to the lack of strong password requirements, increasing the risk of account compromise.
To mitigate CVE-2024-22355, implement strong password policies and ensure that all users are required to create secure passwords.
CVE-2024-22355 affects users of IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software versions 1.10.12.0 through 1.10.18.0.
The main risk associated with CVE-2024-22355 is the increased likelihood of unauthorized access due to weak or compromised passwords.
A potential workaround for CVE-2024-22355 is to manually enforce password complexity requirements for all users until a patch is applied.