CVE Vulnerabilities

CVE-2023-50951

Insertion of Sensitive Information into Log File

Published: Feb 17, 2024 | Modified: Dec 03, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Cloud_pak_for_securityIbm1.10.0.0 (including)1.10.11.0 (including)
Qradar_suiteIbm1.10.12.0 (including)1.10.18.0 (excluding)

Potential Mitigations

References