First published: Wed Aug 14 2024(Updated: )
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID: 287173.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | >=1.10.0.0<=1.10.11.0 | |
IBM QRadar Suite Software | >=1.10.12.0<=1.10.23.0 | |
IBM Cloud Pak for Security | <=1.10.0.0 - 1.10.11.0 | |
IBM QRadar Suite | <=1.10.12.0 - 1.10.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28799 has been categorized with a significant severity level due to the potential for sensitive data disclosure.
To mitigate CVE-2024-28799, it is recommended to apply the latest patches provided by IBM for the affected versions.
CVE-2024-28799 affects IBM QRadar Suite Software versions 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
CVE-2024-28799 may lead to the unexpected disclosure of sensitive data to authorized local users.
CVE-2024-28799 is primarily a concern in non-default configurations, increasing the risk of data exposure.