6.5

CVE-2024-28786

IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmQradar Security Information And Event Manager Version7.5.0 Update-
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_1
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_2
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_3
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_4
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_5
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_6
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_7
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_8
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_9
   LinuxLinux Kernel Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.