IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qradar_security_information_and_event_manager | Ibm | 7.3.0 (including) | 7.3.3 (excluding) |
Qradar_security_information_and_event_manager | Ibm | 7.4.0 (including) | 7.4.3 (excluding) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3 (including) | 7.3.3 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_1 (including) | 7.3.3-fix_pack_1 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_2 (including) | 7.3.3-fix_pack_2 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_3 (including) | 7.3.3-fix_pack_3 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_4 (including) | 7.3.3-fix_pack_4 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_5 (including) | 7.3.3-fix_pack_5 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_6 (including) | 7.3.3-fix_pack_6 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_7 (including) | 7.3.3-fix_pack_7 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_8 (including) | 7.3.3-fix_pack_8 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.3.3-fix_pack_9 (including) | 7.3.3-fix_pack_9 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.4.3 (including) | 7.4.3 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.4.3-fix_pack_1 (including) | 7.4.3-fix_pack_1 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.4.3-fix_pack_2 (including) | 7.4.3-fix_pack_2 (including) |
Qradar_security_information_and_event_manager | Ibm | 7.4.3-fix_pack_3 (including) | 7.4.3-fix_pack_3 (including) |