<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:huawei:emui:12.0.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ohuaweiemui12.0.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 12:02:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ohuaweiemui12.0.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in IBM QRadar SIEM</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-qradar-disclosure/</link><pubDate>Wed, 02 Sep 2026 12:02:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-qradar-disclosure/</guid><description>A vulnerability in IBM QRadar SIEM allows a remote, authenticated attacker to gain unauthorized access to sensitive information.</description><content:encoded><![CDATA[<p>IBM has disclosed a security vulnerability identified as CVE-2024-42037 affecting IBM QRadar SIEM. The vulnerability permits a remote, authenticated attacker to access sensitive information that should otherwise be restricted. Successful exploitation of this flaw leads to unauthorized information disclosure, potentially exposing configuration details, logs, or system data. This issue highlights the importance of access control verification within the SIEM environment. As of the current advisory, there are no reports of widespread active exploitation, but the impact necessitates prompt patch management to prevent potential reconnaissance activities by authorized users who may attempt to exceed their privileges.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows an authenticated user to bypass intended access controls to retrieve restricted system data. Successful exploitation could compromise the confidentiality of security data managed by the SIEM, affecting organizations that rely on QRadar for sensitive log aggregation and incident response. The scope of impact is limited to organizations using vulnerable versions of IBM QRadar SIEM.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching of the affected IBM QRadar SIEM instances as specified by the vendor's security bulletin. Monitor access logs for unusual patterns of data retrieval or high volumes of unexpected queries originating from authenticated user accounts.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category><category>vulnerability</category><category>information-disclosure</category><category>ibm-qradar</category></item></channel></rss>