CVE-2024-22336
published 2024-02-17CVE-2024-22336: IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.19%
9.4th percentile
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279976.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cloud_pak_for_security | 1.10.0.0 – 1.10.11.0 | — |
| ibm | qradar_suite | >= 1.10.12.0 < 1.10.18.0 | 1.10.18.0 |
| ibm | qradar_suite_software | 1.10.12.0 – 1.10.17.0 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5546-xcjq-x5xr: IBM QRadar Suite 1
ghsa_unreviewed·2024-02-17
CVE-2024-22336 [MEDIUM] CWE-532 GHSA-5546-xcjq-x5xr: IBM QRadar Suite 1
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279976.
Red Hat
IBM QRadar Suite: IBM Cloud Pak for Security: Sensitive Information Disclosure in IBM QRadar Suite and IBM Cloud Pak for Security
vendor_redhat·2024-12-02·CVSS 5.1
CVE-2024-22336 [MEDIUM] CWE-532 IBM QRadar Suite: IBM Cloud Pak for Security: Sensitive Information Disclosure in IBM QRadar Suite and IBM Cloud Pak for Security
IBM QRadar Suite: IBM Cloud Pak for Security: Sensitive Information Disclosure in IBM QRadar Suite and IBM Cloud Pak for Security
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279976.
A flaw was found in the IBM QRadar Suite and IBM Cloud Pak for Security. This vulnerability allows a local user to access sensitive information via log files that store potentially sensitive data.
Mitigation: No mitigation is currently available. Please update the possible affected products and components once a fix is available.
Package: odf4/mcg-core-rhel9 (Red Hat Openshift Data Foundation 4) - Fix deferred
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-17
Published