First published: Mon Jul 08 2024(Updated: )
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite | <=1.10.12.0 - 1.10.22.0 | |
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.11.0 | |
IBM QRadar Suite Software | >=1.10.12.0<1.10.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25023 has been classified with a medium severity due to the potential exposure of sensitive information in log files.
To mitigate CVE-2024-25023, it is recommended to review and restrict access to log files containing sensitive information.
CVE-2024-25023 affects IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software versions 1.10.12.0 through 1.10.22.0.
The risk associated with CVE-2024-25023 includes unauthorized access to sensitive information logged by the affected software.
As of now, there is no specific patch released for CVE-2024-25023, but monitoring for updates from IBM is advisable.