Known vulnerabilities in IBM Qradar SIEM - page 55

Software CPE: cpe:2.3:a:ibm_corporation:ibm_qradar_siem:*:*:*:*:*:*:*:*
Total vulnerabilities: 1402
Public exploits: 87
Known exploited (KEV): 24
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Qradar SIEM IBM Qradar SIEM is affected by 1402 known vulnerabilities: 8 critical, 140 high, 438 medium, 816 low Critical High Medium Low

Vulnerabilities (1402)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82572 - Improper Access Control
CVE-2023-43041
CWE-284 Low
No
No
7.5.0 Update Pack 7 IF01 30.10.2023 SB2023103068
#VU71586 - Out-of-bounds write
CVE-2022-40152
CWE-787 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 26.01.2023 SB2023012669
SB2023012670
SB2023013124
and 52 more
#VU71473 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2022-4254
CWE-90 High
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 24.01.2023 SB2023012437
SB2023012440
SB2023012457
and 13 more
#VU71332 - Improper input validation
CVE-2023-22809
CWE-20 Low
Available
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 18.01.2023 SB20230118100
SB20230118104
SB20230118105
and 55 more
#VU71314 - Improper input validation
CVE-2022-40153
CWE-20 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 18.01.2023 SB2023011841
SB2023012670
SB2023021321
and 21 more
#VU71236 - Untrusted Search Path
CVE-2022-4883
CWE-426 Low
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 17.01.2023 SB2023011734
SB2023011737
SB2023011806
and 38 more
#VU70444 - Server-Side Request Forgery (SSRF)
CVE-2022-46364
CWE-918 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 20.12.2022 SB2022122009
SB2023011329
SB2023011707
and 67 more
#VU68844 - Type confusion
CVE-2022-3676
CWE-843 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 31.10.2022 SB2022103129
SB2022111110
SB2022111724
and 60 more
#VU68827 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42890
CWE-94 Low
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 30.10.2022 SB2022103004
SB2022103009
SB2023030742
and 34 more
#VU67811 - Out-of-bounds write
CVE-2022-2964
CWE-787 Low
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 03.10.2022 SB2022100329
SB2022100331
SB2022102079
and 73 more
#VU66756 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-36033
CWE-79 Low
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 25.08.2022 SB2022082508
SB2022101893
SB2022111644
and 44 more
#VU66747 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-31197
CWE-89 High
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 24.08.2022 SB2022082432
SB2022082543
SB2022090901
and 27 more
#VU65864 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-36364
CWE-94 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 28.07.2022 SB2022072832
SB2022122706
SB2023062723
and 3 more
#VU64062 - Integer underflow
CVE-2022-28733
CWE-191 High
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 08.06.2022 SB2022060810
SB2022061540
SB2022061566
and 38 more
#VU63127 - Resource exhaustion
CVE-2021-37136
CWE-400 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 12.05.2022 SB2021101948
SB2022051235
SB2022060838
and 36 more
#VU61810 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-43797
CWE-444 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 02.04.2022 SB2021120923
SB2022040202
SB2022042223
and 49 more
#VU61566 - Exposure of sensitive information to an unauthorized actor
CVE-2021-26401
CWE-200 Low
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 23.03.2022 SB2022032309
SB2022051728
SB2022051831
and 30 more
#VU59924 - Improper input validation
CVE-2021-37137
CWE-20 Medium
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 23.01.2022 SB2022012310
SB2022012745
SB2022012753
and 43 more
#VU59692 - Deserialization of Untrusted Data
CVE-2022-23302
CWE-502 High
No
No
7.5.0 Update Pack 7 IF01 18.01.2022 SB2022011818
SB2022012640
SB2022012641
and 60 more
#VU51511 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-13936
CWE-94 High
No
No
7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 16.03.2021 SB2021031618
SB2021072614
SB2022011911
and 45 more


Showing elements 1081 - 1100 out of 1402