CVE-2024-28786: IBM QRadar SIEM information disclosure
Published Oct 17, 2024
·Updated
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
Affected Software
14 affected components
IBM QRadar SIEM
IBM QRadar SIEM<=7.5 - 7.5.0 UP9 IF03
IBM QRadar Incident Forensics<=7.5 - 7.5.0 UP9 IF03
All of the following
Any of the following
IBM QRadar Security Information and Event Manager=7.5.0
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_1
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_2
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_3
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_4
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_5
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_6
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_7
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_8
IBM QRadar Security Information and Event Manager=7.5.0-update_pack_9
Linux Linux kernel
Event History
Oct 17, 2024
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jan 27, 2025
CVE Published
via MITRE·11:36 PM
Data Sourced
via MITRE·11:36 PM
DescriptionSeverityWeakness
Jan 28, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28786?
CVE-2024-28786 is considered a high severity vulnerability due to the potential exposure of sensitive data in cleartext.
2
How do I fix CVE-2024-28786?
To mitigate CVE-2024-28786, configure IBM QRadar SIEM to use encrypted communication channels for data transmission.
3
What versions of IBM QRadar SIEM are affected by CVE-2024-28786?
CVE-2024-28786 affects IBM QRadar SIEM versions 7.5 to 7.5.0 UP9 IF03.
4
Can CVE-2024-28786 be exploited remotely?
Yes, CVE-2024-28786 can be exploited remotely through man-in-the-middle attacks.
5
What type of data is vulnerable in CVE-2024-28786?
CVE-2024-28786 exposes sensitive or security-critical data transmitted in cleartext.