IBM QRadar Security Information and Event Manager (SIEM) 7.3.3 Fix Pack 11

CPE Details

IBM QRadar Security Information and Event Manager (SIEM) 7.3.3 Fix Pack 11
7.3.3
2022-07-22
13h44 +00:00
2022-08-12
18h37 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.3.3:fix_pack_11:*:*:*:*:*:*

Informations

Vendor

ibm

Product

qradar_security_information_and_event_manager

Version

7.3.3

Update

fix_pack_11

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-39088 2022-07-28 22h15 +00:00 IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID: 216111.
7.8
High
CVE-2022-22424 2022-07-20 17h35 +00:00 IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.
5.5
Medium
CVE-2021-38936 2022-07-20 17h35 +00:00 IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM X-Force ID: 210893.
4.9
Medium
CVE-2021-29755 2022-07-20 17h35 +00:00 IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.
7.5
High
CVE-2021-29779 2021-12-01 17h05 +00:00 IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.
5.9
Medium
CVE-2018-1725 2020-11-05 16h45 +00:00 IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclosure. IBM X-Force ID: 147440.
2.3
Low
CVE-2020-4280 2020-10-08 13h20 +00:00 IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 176140.
8.8
High
CVE-2019-4545 2020-10-08 13h20 +00:00 IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
7.5
High
CVE-2020-4151 2020-04-14 15h10 +00:00 IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-Force ID: 174201.
6.5
Medium
CVE-2019-4559 2020-01-10 15h35 +00:00 IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 166355.
5.3
Medium
CVE-2019-4508 2020-01-10 15h35 +00:00 IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.
7.8
High