CVE-2021-38869: Critical severity IBM QRadar Security Information and Event Manager vulnerability
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
Other sources
IBM QRadar SIEM in some situations may not automatically log users out after they exceede their idle timeout.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38869?
The severity of CVE-2021-38869 is medium with a CVSS score of 4.3.
How does IBM QRadar SIEM handle users exceeding their idle timeout?
In some situations, IBM QRadar SIEM may not automatically log users out after they exceed their idle timeout.
Which versions of IBM QRadar SIEM are affected by CVE-2021-38869?
IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10 are affected by CVE-2021-38869.
How can I fix CVE-2021-38869?
You can fix CVE-2021-38869 by applying the relevant patches provided by IBM for the affected versions of IBM QRadar SIEM.
Where can I find more information about CVE-2021-38869?
You can find more information about CVE-2021-38869 on the IBM X-Force Exchange website and IBM support pages.