First published: Thu Oct 17 2024(Updated: )
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | ||
IBM QRadar Security Information and Event Manager | <=7.5 - 7.5.0 UP9 IF03 | |
IBM Security QRadar Incident Forensics | <=7.5 - 7.5.0 UP9 IF03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28786 is considered a high severity vulnerability due to the potential exposure of sensitive data in cleartext.
To mitigate CVE-2024-28786, configure IBM QRadar SIEM to use encrypted communication channels for data transmission.
CVE-2024-28786 affects IBM QRadar SIEM versions 7.5 to 7.5.0 UP9 IF03.
Yes, CVE-2024-28786 can be exploited remotely through man-in-the-middle attacks.
CVE-2024-28786 exposes sensitive or security-critical data transmitted in cleartext.