CVE-2023-43041: IBM QRadar information disclosure
IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. This vulnerability is due to an incomplete fix for CVE-2022-34352. IBM X-Force ID: 266808.
Other sources
IBM QRadar SIEM is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. This vulnerability is due to an incomplete fix for CVE-2022-34352.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM QRadar vulnerability?
The vulnerability ID for this IBM QRadar vulnerability is CVE-2023-43041.
What is the severity of CVE-2023-43041?
The severity of CVE-2023-43041 is medium with a CVSS score of 6.5.
What is the affected software for CVE-2023-43041?
The affected software for CVE-2023-43041 is IBM QRadar SIEM version 7.5 - 7.5.0 UP7.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by leveraging incomplete fix for CVE-2022-34352 to gain unauthorized access to data from other domains.
Are there any known fixes or mitigations for CVE-2023-43041?
IBM has provided a fix for this vulnerability. Please refer to the IBM support page for detailed information on the fix.