SB2022071331 - Information disclosure in IBM QRadar Network Security
Published: July 13, 2022
Security Bulletin ID
SB2022071331
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2020-4159)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-network-security-is-affected-by-information-exposure-pentest-vulnerabilities-ase-id462657-ase-id462667/"
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-network-security-is-affected-by-information-exposure-pentest-vulnerabilities-ase-id462657-ase-id462667/</a><br><a
- https://www.ibm.com/support/pages/node/6602933"
- https://www.ibm.com/support/pages/node/6602933</a><br><br><br></p>