CVE-2021-29779
Last modified
CVE-2021-29779 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ibm | Qradar Security Information And Event Manager | >= 7.3.0, <= 7.3.3 | — |
| Ibm | Qradar Security Information And Event Manager | >= 7.4.0, <= 7.4.3 | — |
| Ibm | Qradar Security Information And Event Manager | 7.3.3 | Fix Pack 1 |
| Ibm | Qradar Security Information And Event Manager | 7.4.2 | Fix Pack 1 |
| Ibm | Qradar Security Information And Event Manager | 7.4.3 | Fix Pack 1 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/203033VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6520484Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/203033VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6520484Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-29779?
How severe is CVE-2021-29779?
How do I fix CVE-2021-29779?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-29772IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user …9.8
- CVE-2021-29773IBM Security Guardium 10.6 and 11.3 could allow a remote aut…5.4
- CVE-2021-29774IBM Jazz Team Server products could allow an authenticated u…7.5
- CVE-2021-29775IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cl…5.4
- CVE-2021-29776IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticat…4.3
- CVE-2021-29777IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Se…6.5
- CVE-2021-29780IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow …4.7
- CVE-2021-29781IBM Partner Engagement Manager 2.0 could allow a remote atta…9.8
- CVE-2021-29784IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote …4.3
- CVE-2021-29785IBM Security SOAR V42 and V43could allow a remote attacker t…5.9
- CVE-2021-29786IBM Jazz Team Server products stores user credentials in cle…6.5
- CVE-2021-29788IBM Engineering Requirements Quality Assistant On-Premises (…5.4
Are you affected by CVE-2021-29779?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
