CVE-2018-2022 — Sensitive Information Exposure in IBM Qradar Security Information AND Event Manager
CWE-200 — Sensitive Information ExposureCWE-20 — Improper Input ValidationCWE-119 — Improper Restriction of Operations within the Bounds of a Memory BufferCWE-22 — Path TraversalCWE-843 — Type ConfusionCWE-79 — Cross-site ScriptingCWE-80 — Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-326 — Inadequate Encryption StrengthCWE-399CWE-415 — Double FreeCWE-401 — Missing Release of Memory after Effective LifetimeCWE-36 — Absolute Path TraversalCWE-285 — Improper AuthorizationCWE-273 — Improper Check for Dropped PrivilegesCWE-78 — OS Command Injection30 documents11 sources
Severity
5.3MEDIUMNVD
CISA9.8CISA9.1CISA8.8CISA8.6CISA7.8CISA7.5CISA6.6CISA6.1
EPSS
0.2%
top 62.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17
Latest updateJul 7
Description
IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 155346.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4