IBM QRadar Security Information and Event Manager (SIEM) 7.3.3 Patch 8

CPE Details

IBM QRadar Security Information and Event Manager (SIEM) 7.3.3 Patch 8
7.3.3
2021-07-30
14h49 +00:00
2022-04-06
18h07 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.3.3:p8:*:*:*:*:*:*

Informations

Vendor

ibm

Product

qradar_security_information_and_event_manager

Version

7.3.3

Update

p8

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-22424 2022-07-20 17h35 +00:00 IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.
5.5
Moyen
CVE-2021-29779 2021-12-01 17h05 +00:00 IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.
5.9
Moyen
CVE-2021-20399 2021-07-27 11h25 +00:00 IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.
9.1
Critique
CVE-2021-20337 2021-07-26 12h10 +00:00 IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448.
7.5
Haute
CVE-2018-1725 2020-11-05 16h45 +00:00 IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclosure. IBM X-Force ID: 147440.
2.3
Bas
CVE-2020-4280 2020-10-08 13h20 +00:00 IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 176140.
8.8
Haute
CVE-2019-4545 2020-10-08 13h20 +00:00 IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
7.5
Haute
CVE-2020-4151 2020-04-14 15h10 +00:00 IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-Force ID: 174201.
6.5
Moyen
CVE-2019-4559 2020-01-10 15h35 +00:00 IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 166355.
5.3
Moyen
CVE-2019-4508 2020-01-10 15h35 +00:00 IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.
7.8
Haute