CVE-2024-28786: IBM QRadar SIEM information disclosure
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
Other sources
IBM QRadar SIEM transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28786?
CVE-2024-28786 is considered a high severity vulnerability due to the potential exposure of sensitive data in cleartext.
How do I fix CVE-2024-28786?
To mitigate CVE-2024-28786, configure IBM QRadar SIEM to use encrypted communication channels for data transmission.
What versions of IBM QRadar SIEM are affected by CVE-2024-28786?
CVE-2024-28786 affects IBM QRadar SIEM versions 7.5 to 7.5.0 UP9 IF03.
Can CVE-2024-28786 be exploited remotely?
Yes, CVE-2024-28786 can be exploited remotely through man-in-the-middle attacks.
What type of data is vulnerable in CVE-2024-28786?
CVE-2024-28786 exposes sensitive or security-critical data transmitted in cleartext.