

Rewterz Threat Advisory – CVE-2023-45757 – Apache bRPC Vulnerability
October 17, 2023
Rewterz Threat Advisory – Multiple Google Android Vulnerability
October 17, 2023
Rewterz Threat Advisory – CVE-2023-45757 – Apache bRPC Vulnerability
October 17, 2023
Rewterz Threat Advisory – Multiple Google Android Vulnerability
October 17, 2023Severity
Medium
Analysis Summary
CVE-2023-40367 CVSS:5.4
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2023-30994 CVSS:5.9
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Impact
- Cross-Site Scripting
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-40367
- CVE-2023-30994
Affected Vendors
IBM
Affected Products
- IBM QRadar SIEM 7.5.0
Remediation
Refer to IBM Security Advisory for patch, upgrade or suggested workaround information.