CVE-2024-45636
Description
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plaintext, allowing local privileged users to read sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plaintext, allowing local privileged users to read sensitive information.
Vulnerability
IBM Security QRadar EDR versions 3.12 through 3.12.24 store user credentials in plaintext. This vulnerability, identified as CWE-256, resides in the credential storage mechanism and affects all installations within the specified version range. A local privileged user can access the stored credentials by reading the plaintext files [1].
Exploitation
To exploit this vulnerability, an attacker must have local privileged access to the affected system. No user interaction or network access is required beyond the initial system compromise. The attacker can then read the plaintext credential storage, revealing sensitive authentication information [1].
Impact
Successful exploitation leads to the disclosure of user credentials, which may include passwords or other authentication secrets. This increases the risk of further unauthorized access, including potential lateral movement or privilege escalation, depending on the scope of the leaked credentials. The confidentiality impact is high, while integrity and availability are not directly affected [1].
Mitigation
IBM has released version 3.12.25 to address this issue. Users should upgrade to this fixed version as soon as possible. The QRadar EDR operator can be configured for automatic or manual upgrade approval. No workarounds or mitigations are available for versions prior to 3.12.25 [1].
AI Insight generated on Jun 11, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: >=3.12, <=3.12.24
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.