CVE-2024-31905: IBM QRadar Network Packet Capture information disclosure
IBM CounterflowAI could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Other sources
IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31905?
CVE-2024-31905 is classified as a medium-severity vulnerability due to its potential to allow sensitive information exposure through man-in-the-middle attacks.
How do I fix CVE-2024-31905?
To fix CVE-2024-31905, ensure that HTTP Strict Transport Security is properly enabled in IBM QRadar Network Packet Capture.
Who is affected by CVE-2024-31905?
CVE-2024-31905 affects IBM QRadar Network Packet Capture versions 7.5.0 and its update packages.
What could an attacker achieve by exploiting CVE-2024-31905?
An attacker exploiting CVE-2024-31905 could obtain sensitive information through man-in-the-middle techniques.
Is CVE-2024-31905 being actively exploited in the wild?
As of now, there is no public evidence indicating that CVE-2024-31905 is being actively exploited in the wild.