Filtered by vendor Ibm Subscriptions
Filtered by product Security Qradar Edr Subscriptions
Total 11 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-45644 1 Ibm 1 Security Qradar Edr 2025-03-19 4.7 Medium
IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
CVE-2024-45643 1 Ibm 1 Security Qradar Edr 2025-03-15 5.9 Medium
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.
CVE-2024-45638 1 Ibm 1 Security Qradar Edr 2025-03-14 4.1 Medium
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
CVE-2023-35006 1 Ibm 2 Cpe, Security Qradar Edr 2025-03-13 5.4 Medium
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 297165.
CVE-2024-45654 1 Ibm 1 Security Qradar Edr 2025-01-27 4.3 Medium
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.
CVE-2024-45640 1 Ibm 1 Security Qradar Edr 2025-01-07 5.3 Medium
IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.
CVE-2024-45100 1 Ibm 1 Security Qradar Edr 2025-01-07 4.9 Medium
IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources.
CVE-2023-33860 1 Ibm 2 Cpe, Security Qradar Edr 2024-11-21 5.3 Medium
IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 257702.
CVE-2023-33859 1 Ibm 1 Security Qradar Edr 2024-11-21 5.3 Medium
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.
CVE-2024-45642 2 Ibm, Linux 2 Security Qradar Edr, Linux Kernel 2024-11-16 5.3 Medium
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2024-45099 2 Ibm, Linux 2 Security Qradar Edr, Linux Kernel 2024-11-16 3.1 Low
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.