CVE-2023-47728

CWE-2093 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 74.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16

Description

IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM X-Force ID: 272201.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5ibm/qradar_suite_software1.10.12.01.10.22.0
NVDibm/qradar_suite1.10.12.01.10.23.0
CVEListV5ibm/cloud_pak_for_security1.10.0.01.10.11.0
NVDibm/cloud_pak1.10.0.01.10.11.0

🔴Vulnerability Details

2
GHSA
GHSA-fgp2-h88c-m594: IBM QRadar Suite Software 12024-08-16
CVEList
IBM QRadar Suite Software information disclosure2024-08-16
CVE-2023-47728 (HIGH CVSS 7.5) | IBM QRadar Suite Software 1.10.12.0 | cvebase.io