CVE-2014-0837: IBM Qradar Security Information And Event Manager
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected products
- IBM Qradar Security Information And Event Manager: up to and including 7.2.0
Published 2014-01-30. Last modified 2026-06-17.