VDB
CVE-2024-31905
CVE-2024-31905
PUBLISHED
CVSS 5.900000095367432 MEDIUM
IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 289858.
EPSS 0.30% · 20.8th percentile
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.30%
20.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | QRadar Network Packet Capture | 7.5, 7.5 |
| ibm | qradar_network_packet_capture | 7.5.0, 7.5.0, 7.5.0 |
Timeline
- Jul 26, 2024 CVE Published
- Aug 16, 2024 EPSS Score
- Sep 6, 2024 EPSS Score
- Sep 27, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 18, 2024 EPSS Score
- Nov 8, 2024 EPSS Score
- Nov 30, 2024 EPSS Score
- Dec 22, 2024 EPSS Score
- Jan 12, 2025 EPSS Score
- Feb 2, 2025 EPSS Score
- Feb 23, 2025 EPSS Score