IBM QRadar SIEM
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:*:*:*:*:*:*:*
- >= 7.5, <= 7.5.0 UP9 IF03
A vulnerability exists in IBM QRadar SIEM versions 7.5 through 7.5.0 UP9 IF03, where sensitive data is transmitted in cleartext. This lack of encryption could allow an unauthorized actor to intercept security-critical information using man-in-the-middle techniques.
Exploitation of this vulnerability could lead to unauthorized interception of sensitive or security-critical data.
Users are advised to update to IBM QRadar SIEM 7.5.0 UP10. Instructions for downloading this update are available on the IBM Support Fix Central website. For QRadar Incident Forensics users, the same update to version 7.5.0 UP10 should be applied.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.