First published: Fri Mar 14 2025(Updated: )
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security QRadar | <=3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-45638 is critical due to the storage of user credentials in plain text.
To fix CVE-2024-45638, upgrade to a version of IBM Security QRadar EDR that no longer stores credentials in plain text.
CVE-2024-45638 affects IBM Security QRadar EDR version 3.12 and earlier.
CVE-2024-45638 can be exploited by local privileged users who have access to the affected system.
The consequences of CVE-2024-45638 include unauthorized access to sensitive user credentials stored in plain text.