Known vulnerabilities in IBM Qradar SIEM 7.3.1 Patch 1 - page 4

Version: 7.3.1 Patch 1
Software CPE: cpe:2.3:a:ibm_corporation:ibm_qradar_siem:*:*:*:*:*:*:*:*
Total vulnerabilities: 74
Public exploits: 14
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting IBM Qradar SIEM version 7.3.1 Patch 1 IBM Qradar SIEM 7.3.1 Patch 1 is affected by 74 vulnerabilities: 1 critical, 13 high, 29 medium, 31 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU58476 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-29849
CWE-79 Low
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 4 01.12.2021 SB2021120116
#VU56393 - Use After Free
CVE-2021-3715
CWE-416 Low
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 08.09.2021 SB2021090806
SB2021090918
SB2021090919
and 31 more
#VU56242 - Missing Authorization
CVE-2020-27777
CWE-862 Low
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 01.09.2021 SB2020121569
SB2021090127
SB2021090130
and 13 more
#VU56241 - Command injection
CVE-2021-29154
CWE-77 Low
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 01.09.2021 SB2021040820
SB2021090127
SB2021090128
and 44 more
#VU56240 - Memory corruption
CVE-2021-29650
CWE-119 Low
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 01.09.2021 SB2021033033
SB2021090127
SB2021090128
and 44 more
#VU56017 - Out-of-bounds write
CVE-2021-22555
CWE-787 Low
Public exploit available
Exploited
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 20.08.2021 SB2021070718
SB2021082206
SB2021083120
and 53 more
#VU55257 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2021-32399
CWE-362 Low
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 22.07.2021 SB2021051144
SB2021072247
SB2021072248
and 58 more
#VU53232 - Missing release of memory after effective lifetime
CVE-2021-32028
CWE-401 Medium
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 4 13.05.2021 SB2021051316
SB2021051605
SB2021052507
and 41 more
#VU53231 - Integer overflow
CVE-2021-32027
CWE-190 Medium
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 4 13.05.2021 SB2021051316
SB2021051605
SB2021052507
and 43 more
#VU52448 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-2161
CWE-94 Medium
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 21.04.2021 SB2021042115
SB2021042116
SB2021042117
and 45 more
#VU17335 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2018-1733
CWE-451 Low
No
No
7.2.8 Patch 14, 7.3.1 Patch 7 24.01.2019 SB2019013108
#VU14121 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1612
CWE-200 Low
Public exploit available
No
7.2.8 Patch 12 30.07.2018 SB2018060610
#VU13045 - Command injection
CVE-2018-1418
CWE-77 Low
Public exploit available
No
- 30.05.2018 SB2018053002
#VU37620 - Exposure of sensitive information to an unauthorized actor
CVE-2017-15713
CWE-200 Medium
No
No
7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4 19.01.2018 SB2017060509
SB2021120219
SB2021120336
and 7 more


Showing elements 61 - 80 out of 74