CVE-2021-29776

MEDIUM

IBM QRadar SIEM <7.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6574787
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/203030

Scores

CVSS v3 4.3
EPSS 0.0031
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (4)
ibm/qradar_security_information_and_event_manager 7.3.3 (10 CPE variants)
ibm/qradar_security_information_and_event_manager 7.4.3 (4 CPE variants)
ibm/qradar_security_information_and_event_manager 7.5.0
ibm/qradar_security_information_and_event_manager 7.3.0 - 7.3.3
Published Apr 27, 2022
Tracked Since Feb 18, 2026