CVE-2024-28799: IBM QRadar Suite Software information disclosure
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID: 287173.
Other sources
IBM QRadar Suite Software displays sensitive data improperly during back-end commands which may result in the unexpected disclosure of this information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28799?
CVE-2024-28799 has been categorized with a significant severity level due to the potential for sensitive data disclosure.
How do I fix CVE-2024-28799?
To mitigate CVE-2024-28799, it is recommended to apply the latest patches provided by IBM for the affected versions.
Which products are affected by CVE-2024-28799?
CVE-2024-28799 affects IBM QRadar Suite Software versions 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
What is the impact of CVE-2024-28799?
CVE-2024-28799 may lead to the unexpected disclosure of sensitive data to authorized local users.
Is CVE-2024-28799 exploitable in default configurations?
CVE-2024-28799 is primarily a concern in non-default configurations, increasing the risk of data exposure.