First published: Mon Mar 17 2025(Updated: )
IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=1.0.0 - 2.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49822 is classified as a medium severity vulnerability due to the potential impact of unauthorized network requests.
To fix CVE-2024-49822, upgrade your IBM QRadar Advisor to a version later than 2.6.5.
CVE-2024-49822 affects users of IBM QRadar Advisor versions 1.0.0 through 2.6.5.
CVE-2024-49822 is a server-side request forgery (SSRF) vulnerability.
Attackers exploiting CVE-2024-49822 can send unauthorized requests which may lead to network enumeration and facilitate other attacks.