
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
IBM QRadar SIEM in some situations may not automatically log users out after they exceed their idle timeout (CVE-2021-38869). This vulnerability affects IBM QRadar SIEM versions 7.5.0 antecedent to 7.5.0 UP1, versions 7.3.3 antecedent to 7.3.3 FP11, and versions 7.4.3 antecedent to 7.4.3 FP5 (IBM Security Bulletin).
The vulnerability has a CVSS Base score of 4.3 and CVSS Vector of (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), indicating physical access is required with low attack complexity and no privileges needed. The vulnerability affects session management functionality, specifically related to idle timeout enforcement (IBM Security Bulletin).
This vulnerability could potentially allow unauthorized access to the system if a user's session remains active beyond the intended timeout period, potentially exposing sensitive information and system functionality to unauthorized users (IBM Security Bulletin).
IBM recommends customers update their systems to the following fixed versions: QRadar/QRM/QVM/QRIF/QNI 7.5.0 UP1 for 7.5.0 GA, QRadar/QRM/QVM/QRIF/QNI 7.4.3 FP5 for 7.4.3 versions, and QRadar/QRM/QVM/QRIF/QNI 7.3.3 FP11 for 7.3.3 versions. No workarounds are available (IBM Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”