National CSIRT-CY | National Computer Security Incident Response Team of Cyprus

Η Εθνική Ομάδα Αντιμετώπισης Ηλεκτρονικών Επιθέσεων προβλέπει την αύξηση της ηλεκτρονικής ασφαλείας ενισχύοντας την προστασία του κυβερνοχώρου των Εθνικών Κρίσιμων Πληροφοριακών Υποδομών, των τραπεζών και των παροχών επικοινωνίας της Κυπριακής Δημοκρατίας.

Security Update: IBM QRadar SIEM

16 May 2024

The Digital Security Authority (DSA) wants to bring to your attention, that IBM released Security updates to address an information disclosure vulnerability in QRadar SIEM.

 

Technical Details

Vulnerability Details:

  • CVE-2024-27269 - CVSS 3.0 Base Score: 6.8
  • IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants.

Affected Products:

  • IBM QRadar SIEM 7.5.0

Fixed Versions:

  • Refer to IBM Security Bulletin 7150684 for a patch IBM QRadar SIEM v 7.5.0 UP8 IF02, upgrade, or suggested workaround information.

 

Recommendations

The Digital Security Authority recommends installing the fixed versions released by IBM.

 

References

https://www.ibm.com/support/pages/security-bulletin-ibm-qradar-siem-contains-multiple-vulnerabilities-14

 

The information presented in this report is based on available data up to the 15th of May 2024.

Cyber threats require heightened defences

Working towards a trusted and cyber secure Europe

Protect your cyber hygiene

Cyber Europe 2022 [exercise]