IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
The vulnerability classified as CWE-260 (Password in Configuration File) consists of sensitive data — potentially including passwords or keys — being stored in configuration files in a manner accessible without authentication. An unauthenticated user with network access to the environment (AV:A vector — access from local/adjacent network) can read these files and obtain critical data. The lack of authentication requirement (PR:N) and user interaction (UI:N) means that the attack can be performed in a fully automated manner.
An attacker can obtain highly sensitive information from configuration files, which may lead to further system takeover, privilege escalation, or lateral movement within the infrastructure. The scope of the vulnerability includes complete breach of confidentiality, integrity, and availability (S:C, C:H, I:H, A:H).
Patches available from the vendor should be applied according to the references: https://www.ibm.com/support/pages/node/7235432
IBM QRadar Suite Software in versions from 1.10.12.0 to 1.11.2.0 and IBM Cloud Pak for Security in versions from 1.10.0.0 to 1.10.11.0.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HIBM Cloud Pak For Security
APPIbm1.10.0.0 – 1.10.11.0IBM Qradar Suite
APPIbm1.10.12.0 – 1.11.2.0
Related vulnerabilities
IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)
Nieprawidłowa autoryzacja w IBM Cloud Pak for Security
CSV Injection w IBM Cloud Pak for Security umożliwia zdalne wykonanie kodu
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0...
IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21...