VulnerabilityModified
CVE-2021-29779
IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques.
MEDIUM 5.9EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- ibm/qradar security information and event manager
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/203033VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6520484Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/203033VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6520484Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.