CVE-2024-25023: IBM QRadar Suite Software information disclosure
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
Other sources
IBM QRadar Suite stores potentially sensitive information in log files that could be read by a local user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25023?
CVE-2024-25023 has been classified with a medium severity due to the potential exposure of sensitive information in log files.
How do I fix CVE-2024-25023?
To mitigate CVE-2024-25023, it is recommended to review and restrict access to log files containing sensitive information.
Which versions are affected by CVE-2024-25023?
CVE-2024-25023 affects IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software versions 1.10.12.0 through 1.10.22.0.
What risks are associated with CVE-2024-25023?
The risk associated with CVE-2024-25023 includes unauthorized access to sensitive information logged by the affected software.
Is there a patch available for CVE-2024-25023?
As of now, there is no specific patch released for CVE-2024-25023, but monitoring for updates from IBM is advisable.