Tuesday, January 28, 2025
HomeCyber Security NewsIBM QRadar SIEM Vulnerability Enables XSS Attack and Information Disclosure

IBM QRadar SIEM Vulnerability Enables XSS Attack and Information Disclosure

Published on

SIEM as a Service

Follow Us on Google News

IBM QRadar is a popular SIEM (Security Incident and Event Management) tool organizations use to detect and monitor threats.

The IBM QRadar SIEM can be used in the form of a physical appliance, a software-only solution, or a virtual appliance.

As of 2023, It is being used by over 1130 companies worldwide as part of their SIEM.

IBM discovered three new vulnerabilities in the IBM SIEM and CVEs, and necessary fixes were also released.

These vulnerabilities were related to Cryptography, XSS, and information disclosure which was discovered by IBM’s Security Ethical Hacking team.

IBM QRadar SIEM Flaw

CVE-2023-26276: Weak Cryptographic Algorithm

This vulnerability exists due to the use of a weaker or expected cryptographic algorithm in the QRadar tool, which could allow a threat actor to decrypt highly sensitive information.

This vulnerability was given a CVSS Score of 5.9 (medium)

CVE-2023-26274: Cross-Site Scripting (XSS)

An attacker can exploit this vulnerability to embed arbitrary JS code in the Web UI that can alter the functionality that can lead to credentials disclosure through XSS on a trusted session.

This vulnerability was given a CVSS Score of 4.6 (medium).

CVE-2022-34352: Information Disclosure

This vulnerability allows a delegated Admin tenant with a specific domain security profile to see other domain data.

This vulnerability was given a CVSS Score of 6.5 (medium).

Affected Products

Affected Product(s)Version(s)
IBM QRadar SIEM7.5.0 – 7.5.0 UP5

Remediation and Fix

ProductVersionRemediation/First Fix
IBM QRadar SIEM7.5.0 7.5.0 UP6

There are no workarounds or mitigations available. IBM recommended all its users patch their IBM QRadar SIEM by upgrading it to the latest version.

“AI-based email security measures Protect your business From Email Threats!” – .

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...

GitHub Vulnerability Exposes User Credentials via Malicious Repositories

A cybersecurity researcher recently disclosed several critical vulnerabilities affecting Git-related projects, revealing how improper...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...