Описание
The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-0837
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90680
- http://osvdb.org/102552
- http://seclists.org/fulldisclosure/2014/Jan/166
- http://secunia.com/advisories/56653
- http://www-01.ibm.com/support/docview.wss?uid=swg21663066
- http://www.securityfocus.com/bid/65127
EPSS
Процентиль: 49%
0.00262
Низкий
CVE ID
Связанные уязвимости
nvd
около 12 лет назад
The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
EPSS
Процентиль: 49%
0.00262
Низкий