IBM QRadar SIEM是美国国际商业机器(IBM)公司的一套利用安全智能保护资产和信息远离高级威胁的解决方案。该方案提供对整个IT架构范围进行监督、生成详细的数据访问和用户活动报告等功能。 IBM QRadar SIEM存在安全漏洞,该漏洞源于以明文形式传输敏感或安全关键数据,导致攻击者可以绕过数据访问限制读取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | QRadar SIEM | 7.5 |
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:-:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-37526 | 6.5 MEDIUM | IBM Watson Query on Cloud Pak for Data information disclosure |
| CVE-2023-52292 | 6.4 MEDIUM | IBM Sterling File Gateway cross-site scripting |
| CVE-2024-38325 | 5.9 MEDIUM | IBM Storage Defender information disclosure |
| CVE-2024-38320 | 5.9 MEDIUM | IBM Storage Protect for Virtual Environments: Data Protection for VMware information discl |
| CVE-2024-27256 | 5.9 MEDIUM | IBM MQ Operator information disclosure |
| CVE-2023-46187 | 5.4 MEDIUM | IBM InfoSphere Master Data Management cross-site scripting |
| CVE-2024-37527 | 5.4 MEDIUM | IBM OpenPages with Watson cross-site scripting |
| CVE-2024-28771 | 4.8 MEDIUM | IBM Security Directory Integrator information disclosure |
| CVE-2024-28770 | 4.8 MEDIUM | IBM Security Directory Integrator information disclosure |
| CVE-2024-22316 | 4.3 MEDIUM | IBM Sterling File Gateway improper access control |
| CVE-2023-47159 | 4.3 MEDIUM | IBM Sterling File Gateway information disclosure |
| CVE-2024-28766 | 2.4 LOW | IBM Security Directory Integrator information disclosure |
No comments yet