cve/2023/CVE-2023-47742.md

20 lines
1.1 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-47742](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47742)
![](https://img.shields.io/static/v1?label=Product&message=Cloud%20Pak%20for%20Security&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=QRadar%20Suite%20Products&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.10.0.0%3C%3D%201.10.11.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.10.12.0%3C%3D%201.10.18.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-300%20Channel%20Accessible%20by%20Non-Endpoint%20('Man-in-the-Middle')&color=brighgreen)
### Description
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information using man in the middle techniques due to not correctly enforcing all aspects of certificate validation in some circumstances. IBM X-Force ID: 272533.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds