CVE-2018-1648
UnknownEPSS 1.07%
Last modified
CVE-2018-1648 is a vulnerability of currently unknown severity. IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Qradar Incident Forensics | >= 7.2.0, < 7.2.8 |
| Ibm | Qradar Incident Forensics | >= 7.3.0, < 7.3.1 |
| Ibm | Qradar Incident Forensics | 7.2.8 |
| Ibm | Qradar Incident Forensics | 7.3.1 |
References
- http://www.ibm.com/support/docview.wss?uid=ibm10737027Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/144653VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10737027Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/144653VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1648?
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.
How severe is CVE-2018-1648?
Severity scoring for CVE-2018-1648 is pending analysis. The EPSS model estimates a 1.07% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1648?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-16474A stored xss in tianma-static module versions <=1.0.4 allows…
- CVE-2018-16475A Path Traversal in Knightjs versions <= 0.0.1 allows an att…
- CVE-2018-16476A Broken Access Control vulnerability in Active Job versions…
- CVE-2018-16477A bypass vulnerability in Active Storage >= 5.2.0 for Google…
- CVE-2018-16478A Path Traversal in simplehttpserver versions <=0.2.1 allows…
- CVE-2018-16479Path traversal vulnerability in http-live-simulator <1.0.7 c…
- CVE-2018-16480A XSS vulnerability was found in module public <0.1.4 that a…
- CVE-2018-16481A XSS vulnerability was found in html-page <=2.1.1 that allo…
- CVE-2018-16482A server directory traversal vulnerability was found on node…7.5
- CVE-2018-16483A deficiency in the access control in module express-cart <=…
- CVE-2018-16484A XSS vulnerability was found in module m-server <1.4.2 that…
- CVE-2018-16485Path Traversal vulnerability in module m-server <1.4.1 allow…
Are you affected by CVE-2018-1648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
