CVE-2018-1648Inadequate Encryption Strength in IBM Qradar Incident Forensics

Severity
7.5HIGHNVD
EPSS
0.1%
top 70.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5
Latest updateMay 14

Description

IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDibm/qradar_incident_forensics7.2.07.2.8+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c847-9386-rf38: IBM QRadar SIEM 72022-05-14
CVEList
CVE-2018-1648: IBM QRadar SIEM 72018-12-05

💥Exploits & PoCs

1
Exploit-DB
PRTG Network Monitor < 18.1.39.1648 - Stack Overflow (Denial of Service)2018-04-23
CVE-2018-1648 — Inadequate Encryption Strength in IBM | cvebase