Vulnerability Details CVE-2015-2008
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.3%
CVSS Severity
CVSS v3 Score 4.4
CVSS v2 Score 3.5
Products affected by CVE-2015-2008
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5