IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qradar_security_information_and_event_manager | Ibm | 7.1.2 (including) | 7.2.8 (excluding) |
Qradar_security_information_and_event_manager | Ibm | 7.2.8 (including) | 7.2.8 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.2.8-p1 (including) | 7.2.8-p1 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.2.8-p2 (including) | 7.2.8-p2 (including) |