CVE-2024-22355: IBM QRadar Suite information dislosure
IBM CloudPak Bedrock does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Other sources
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 280781.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22355?
The severity of CVE-2024-22355 is considered high due to the lack of strong password requirements, increasing the risk of account compromise.
How do I fix CVE-2024-22355?
To mitigate CVE-2024-22355, implement strong password policies and ensure that all users are required to create secure passwords.
Who is affected by CVE-2024-22355?
CVE-2024-22355 affects users of IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software versions 1.10.12.0 through 1.10.18.0.
What are the risks associated with CVE-2024-22355?
The main risk associated with CVE-2024-22355 is the increased likelihood of unauthorized access due to weak or compromised passwords.
Is there a workaround for CVE-2024-22355?
A potential workaround for CVE-2024-22355 is to manually enforce password complexity requirements for all users until a patch is applied.