CVE-2024-45638: IBM QRadar EDR information disclosure
Published Mar 14, 2025
·Updated
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
Affected Software
3 affected components
IBM Security QRadar EDR<=3.12
All of the following
IBM Security QRadar EDR>=3.12<3.12.16
Linux Linux kernel
Event History
Mar 14, 2025
CVE Published
via IBM·12:00 AM
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45638?
The severity of CVE-2024-45638 is critical due to the storage of user credentials in plain text.
2
How do I fix CVE-2024-45638?
To fix CVE-2024-45638, upgrade to a version of IBM Security QRadar EDR that no longer stores credentials in plain text.
3
What products are affected by CVE-2024-45638?
CVE-2024-45638 affects IBM Security QRadar EDR version 3.12 and earlier.
4
Who can exploit CVE-2024-45638?
CVE-2024-45638 can be exploited by local privileged users who have access to the affected system.
5
What are the consequences of CVE-2024-45638?
The consequences of CVE-2024-45638 include unauthorized access to sensitive user credentials stored in plain text.