Local Information Disclosure Vulnerability in IBM QRadar SIEM
CVE-2022-22424
5.1MEDIUM
Summary
IBM QRadar SIEM versions 7.3, 7.4, and 7.5 are affected by a local information disclosure vulnerability that arises from improper file permissions set on the TLS key file. This misconfiguration could allow a local user to access sensitive information, potentially compromising the security of the application and the confidentiality of the data it protects. It is critical for users to ensure proper permission settings to mitigate the risks associated with this vulnerability.
Affected Version(s)
QRadar SIEM 7.3.0
QRadar SIEM 7.4.0
QRadar SIEM 7.5.0
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved