Known vulnerabilities in IBM Qradar SIEM - page 59

Software CPE: cpe:2.3:a:ibm_corporation:ibm_qradar_siem:*:*:*:*:*:*:*:*
Total vulnerabilities: 1402
Public exploits: 87
Known exploited (KEV): 24
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Qradar SIEM IBM Qradar SIEM is affected by 1402 known vulnerabilities: 8 critical, 140 high, 438 medium, 816 low Critical High Medium Low

Vulnerabilities (1402)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77127 - Information Exposure Through Log Files
CVE-2023-20859
CWE-532 Medium
No
No
7.5.0 Update Pack 6 09.06.2023 SB2023060927
SB2023070708
SB2023100926
#VU74824 - Double Free
CVE-2023-1999
CWE-415 High
No
No
7.5.0 Update Pack 6 11.04.2023 SB2023041129
SB2023041192
SB2023042845
and 40 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
7.5.0 Update Pack 6 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU73175 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31159
CWE-22 Medium
No
No
- 08.03.2023 SB2023030823
SB2023030915
SB2023042635
and 15 more
#VU72575 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48339
CWE-78 High
No
No
7.5.0 Update Pack 7 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 50 more
#VU72250 - Out-of-bounds write
CVE-2023-0767
CWE-787 Medium
No
No
7.5.0 Update Pack 6 15.02.2023 SB2023021549
SB2023021551
SB2023021552
and 84 more
#VU72123 - Deserialization of Untrusted Data
CVE-2023-25194
CWE-502 Low
Available
No
7.5.0 Update Pack 6 11.02.2023 SB2023021101
SB2023030952
SB2023040419
and 40 more
#VU71239 - Integer overflow
CVE-2022-23521
CWE-190 High
No
No
7.5.0 Update Pack 6 17.01.2023 SB2023011739
SB2023011741
SB2023011804
and 52 more
#VU71238 - Heap-based Buffer Overflow
CVE-2022-41903
CWE-122 High
No
No
7.5.0 Update Pack 6 17.01.2023 SB2023011739
SB2023011741
SB2023011804
and 51 more
#VU70442 - Stack-based buffer overflow
CVE-2022-4378
CWE-121 Low
No
No
7.5.0 Update Pack 6 20.12.2022 SB2022122008
SB2022122123
SB2022122124
and 124 more
#VU69297 - Use After Free
CVE-2022-42703
CWE-416 Low
Available
No
7.5.0 Update Pack 6 14.11.2022 SB2022111444
SB2022111701
SB2022111702
and 87 more
#VU69296 - Out-of-bounds write
CVE-2022-43750
CWE-787 Low
No
No
7.5.0 Update Pack 6 14.11.2022 SB2022111443
SB2022113032
SB2022113033
and 72 more
#VU69283 - Out-of-bounds write
CVE-2022-40151
CWE-787 Medium
No
No
7.5.0 Update Pack 6 14.11.2022 SB2022111420
SB2022122822
SB2023012670
and 32 more
#VU69151 - Security Features
CVE-2022-38023
CWE-254 High
No
No
7.5.0 Update Pack 6 09.11.2022 SB2022110912
SB2022121537
SB2022121801
and 46 more
#VU68832 - Resource exhaustion
CVE-2022-42004
CWE-400 Medium
No
No
7.5.0 Update Pack 6 31.10.2022 SB2022103116
SB2022103117
SB2022111404
and 122 more
#VU68635 - Deserialization of Untrusted Data
CVE-2022-42003
CWE-502 Medium
No
No
7.5.0 Update Pack 6 25.10.2022 SB2022102509
SB2022102510
SB2022103117
and 208 more
#VU67489 - Resource exhaustion
CVE-2022-34917
CWE-400 Medium
No
No
7.5.0 Update Pack 6 20.09.2022 SB2022092020
SB2022100556
SB2022110304
and 21 more
#VU66153 - Heap-based Buffer Overflow
CVE-2022-37434
CWE-122 High
Available
No
7.5.0 Update Pack 6 07.08.2022 SB2022080705
SB2022081833
SB2022081851
and 154 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
7.5.0 Update Pack 6 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU27250 - Improper input validation
CVE-2015-0254
CWE-20 Medium
No
No
7.5.0 Update Pack 6 23.04.2020 SB2020042337
SB2015092202
SB2017062712
and 6 more


Showing elements 1161 - 1180 out of 1402