HIGH · 8.4

CVE-2023-22875

IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.

Vulnerability Description

IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.

CVSS Score

8.4

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
IbmQradar Security Information And Event Manager7.4.0
LinuxLinux Kernel-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-22875?

CVE-2023-22875 is a vulnerability with a CVSS score of 8.4 (HIGH). IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.

How severe is CVE-2023-22875?

CVE-2023-22875 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-22875?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Qradar Security Information And Event Manager, Linux Linux Kernel.