CVE-2024-56464: IBM QRadar SIEM is affected by an information disclosure vulnerability
IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update.
Other sources
IBM QRadar SIEM could allow a privileged user to enumerate directory information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM QRadar SIEMto a version that resolves this vulnerability.Fixed in 7.5.0 UP14 IF02
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56464?
CVE-2024-56464 is considered a medium severity information disclosure vulnerability.
How do I fix CVE-2024-56464?
To fix CVE-2024-56464, upgrade to the latest version of IBM QRadar SIEM as specified by IBM.
What type of vulnerability is CVE-2024-56464?
CVE-2024-56464 is classified as an information disclosure vulnerability.
Who is affected by CVE-2024-56464?
CVE-2024-56464 affects users of IBM QRadar SIEM versions 7.5 to 7.5.0 UP14 IF01.
What could a privileged user do in the context of CVE-2024-56464?
A privileged user could potentially enumerate sensitive directory information due to CVE-2024-56464.