CVE-2024-45644
CVE-2024-45644 is a medium-severity vulnerability in Ibm Security Qradar Edr with a CVSS 3.x base score of 4.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-434.
Key facts
- Severity: Medium (CVSS 3.x base score 4.7)
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-54114
- Weakness: CWE-434
- Affected product: Ibm Security Qradar Edr
- Published:
- Last modified:
Description
IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
Frequently asked questions
- What is CVE-2024-45644?
- IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
- How severe is CVE-2024-45644?
- CVE-2024-45644 has a CVSS 3.x base score of 4.7, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2024-45644 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-45644?
- CVE-2024-45644 affects Ibm Security Qradar Edr. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-45644?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-45644 have an EU (EUVD) identifier?
- Yes. CVE-2024-45644 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-54114.
- When was CVE-2024-45644 published?
- CVE-2024-45644 was published on 2025-03-19 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:ibm:security_qradar_edr:3.12:*:*:*:*:*:*:*
More vulnerabilities in Ibm Security Qradar Edr
- CVE-2024-45641 — Medium (CVSS 6.5): IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate…
- CVE-2023-33861 — Medium (CVSS 6.5): IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication…
- CVE-2025-36376 — Medium (CVSS 6.3): IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow…
- CVE-2024-45643 — Medium (CVSS 5.9): IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt…
- CVE-2023-35006 — Medium (CVSS 5.4): IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which…
- CVE-2024-45640 — Medium (CVSS 5.3): IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks…
All CVEs affecting Ibm Security Qradar Edr →
Other CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities
- CVE-2026-75949 — Critical (CVSS 10.0): Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 -…
- CVE-2026-74803 — Critical (CVSS 10.0): Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts…
- CVE-2026-66665 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-61900 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla…
- CVE-2026-61424 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla…
- CVE-2026-57719 — Critical (CVSS 10.0): Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using…
Browse all CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities →