
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM QRadar SIEM versions 7.3, 7.4, and 7.5 contains a vulnerability where the system does not perform proper certificate validation for some inter-host communications (IBM Support). The vulnerability was assigned CVE-2021-29755 and was disclosed in July 2022.
The vulnerability has a CVSS Base score of 5.9 with vector (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). This indicates that the vulnerability is network exploitable but requires high attack complexity, needs no privileges or user interaction, has high confidentiality impact but no impact on integrity or availability (IBM Support).
The improper certificate validation could potentially allow an attacker to intercept and access sensitive information during inter-host communications between QRadar SIEM components (IBM Support).
IBM has released fixes for the affected versions: QRadar SIEM 7.3.3 Fix Pack 12, QRadar SIEM 7.4.3 Fix Pack 6, and QRadar SIEM 7.5.0 Update Pack 2. IBM encourages customers to update their systems promptly. No workarounds are available (IBM Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."