CVE-2023-50951

MEDIUM

IBM Cloud Pak For Security < 1.10.11.0 - Log Information Exposure

Title source: rule
STIX 2.1

Description

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7118604

Scores

CVSS v3 4.0
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (2)
ibm/cloud_pak_for_security 1.10.0.0 - 1.10.11.0
ibm/qradar_suite 1.10.12.0 - 1.10.18.0
Published Feb 17, 2024
Tracked Since Feb 18, 2026