Lucene search

K
ibmIBM814B1FFB6B16F2540617CCF8FB96919BB596BB7D283CC98F9365A95C5B062C78
HistoryJul 10, 2019 - 8:10 p.m.

Security Bulletin: An IBM QRadar SIEM protocol is vulnerable to Incorrect Permission Assignment (CVE-2018-2024)

2019-07-1020:10:01
www.ibm.com
7

0.001 Low

EPSS

Percentile

23.7%

Summary

The Log file protocol could allow permissions to a resource to be read or modified by unintended actors.

Vulnerability Details

CVEID: CVE-2018-2024
**Description:**IBM QRadar specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
**CVSS Base Score:**4.2
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/155350&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products and Versions

7.2.0-QRADAR-PROTOCOL-LogFileProtocol-7.2-20180625094737 and prior

7.3.0-QRADAR-PROTOCOL-LogFileProtocol-7.3-20180625134822 and prior

Remediation/Fixes

7.2.0-QRADAR-PROTOCOL-LogFileProtocol-7.2-20190617154048

7.3.0-QRADAR-PROTOCOL-LogFileProtocol-7.3-20190617194019

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

23.7%

Related for 814B1FFB6B16F2540617CCF8FB96919BB596BB7D283CC98F9365A95C5B062C78