CVE-2019-4654Improper Certificate Validation in IBM Qradar Security Information AND Event Manager

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 68.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 24

Description

IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-ForceID: 170965.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.5

Affected Packages2 packages

CVEListV5ibm/qradar7.3.0, 7.3.3.Patch2+1

🔴Vulnerability Details

2
GHSA
GHSA-mp6c-f77j-f7rm: IBM QRadar 72022-05-24
CVEList
CVE-2019-4654: IBM QRadar 72020-04-15
CVE-2019-4654 — Improper Certificate Validation in IBM | cvebase