CVE-2021-38878: High severity ibm qradar security information and event manager vulnerability
Published Apr 12, 2022
·Updated
IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.
Other sources
IBM QRadar could allow a malicious actor to impersonate an actor due to key exchange without entity authentication.
— IBM
Affected Software
21 affected componentsFixes available
IBM QRadar Security Information and Event Manager>=7.3.0<7.3.3
IBM QRadar Security Information and Event Manager>=7.4.0<7.4.3
IBM QRadar Security Information and Event Manager=7.3.3
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_1
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_2
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_3
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_4
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_5
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_6
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_7
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_8
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_9
IBM QRadar Security Information and Event Manager=7.4.3
IBM QRadar Security Information and Event Manager=7.4.3-fix_pack_1
IBM QRadar Security Information and Event Manager=7.4.3-fix_pack_2
IBM QRadar Security Information and Event Manager=7.4.3-fix_pack_3
IBM QRadar Security Information and Event Manager=7.5.0
Linux Linux kernel
IBM QRadar SIEM<=7.5.0 GA
IBM QRadar SIEM<=7.4.3 GA - 7.4.3 FP4
IBM QRadar SIEM<=7.3.3 GA - 7.3.3 FP10
Remediation
Patch Available
Event History
Apr 12, 2022
CVE Published
via IBM·12:00 AM
Apr 27, 2022
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38878.
2
What is the severity of CVE-2021-38878?
The severity of CVE-2021-38878 is high (7.5).
3
Which IBM QRadar versions are affected by CVE-2021-38878?
IBM QRadar versions 7.3, 7.4, and 7.5 are affected by CVE-2021-38878.
4
How can I patch or fix CVE-2021-38878?
You can patch or fix CVE-2021-38878 by applying the available patches provided by IBM. Please refer to the IBM support page for more information and download links.
5
Where can I find more information about CVE-2021-38878?
You can find more information about CVE-2021-38878 on the IBM X-Force Exchange website and the IBM support page.