Severity
5.3MEDIUMNVD
CISA9.8CISA9.1CISA8.8CISA8.6CISA7.8CISA7.5CISA6.6CISA6.1
EPSS
0.2%
top 62.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateJul 7

Description

IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 155346.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/qradar_siem7.2, 7.3+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pr6v-j9rj-hrwf: IBM QRadar SIEM 72022-05-24
CVEList
CVE-2018-2022: IBM QRadar SIEM 72019-07-17

💥Exploits & PoCs

1
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution2023-07-07

📋Vendor Advisories

17
Oracle
Oracle Oracle Siebel CRM Risk Matrix: eDetailing (PDF Viewer) — CVE-2018-51582022-10-15
CISA
Apple Multiple Products Memory Corruption Vulnerability2022-06-27
CISA
Adobe Acrobat and Reader Double Free Vulnerability2022-06-08
CISA
QNAP NAS File Station Cross-Site Scripting Vulnerability2022-05-24
CISA
LG N1A1 NAS Remote Command Execution Vulnerability2022-03-25

💬Community

2
HackerOne
DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)2023-01-12
HackerOne
DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)2022-09-28
CVE-2018-2022 — Sensitive Information Exposure in IBM | cvebase