CVE-2023-47742

Severity
5.9MEDIUM
EPSS
0.0%
top 86.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3

Description

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information using man in the middle techniques due to not correctly enforcing all aspects of certificate validation in some circumstances. IBM X-Force ID: 272533.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

CVEListV5ibm/qradar_suite_products1.10.12.01.10.18.0
NVDibm/qradar_suite1.10.12.01.10.18.0
CVEListV5ibm/cloud_pak_for_security1.10.0.01.10.11.0
NVDibm/cloud_pak1.10.0.01.10.11.0

🔴Vulnerability Details

2
GHSA
GHSA-wp3w-g939-hq9w: IBM QRadar Suite Products 12024-03-03
CVEList
IBM QRadar Suite information dislosure2024-03-03
CVE-2023-47742 (MEDIUM CVSS 5.9) | IBM QRadar Suite Products 1.10.12.0 | cvebase.io