Skip to main content
Vulnerability Database/CVE-2024-31905

CVE-2024-31905: IBM QRadar Network Packet Capture Disclosure

CVE-2024-31905 is an information disclosure flaw in IBM QRadar Network Packet Capture 7.5 that exposes sensitive data through man-in-the-middle attacks. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2024-31905 Overview

CVE-2024-31905 affects IBM QRadar Network Packet Capture 7.5. The product fails to properly enable HTTP Strict Transport Security (HSTS) on its web interface. A remote attacker positioned between a user and the appliance can intercept or downgrade HTTPS traffic to obtain sensitive information. The weakness is classified as cleartext transmission of sensitive information [CWE-319]. Exploitation requires man-in-the-middle (MITM) positioning on the network path, which raises attack complexity but does not require authentication or user interaction. The flaw affects QRadar Network Packet Capture 7.5.0 through update package 7, as listed in IBM's advisory.

Critical Impact

Attackers with network path control can intercept administrative sessions and extract sensitive data by forcing HTTP downgrades against the QRadar packet capture web interface.

Affected Products

  • IBM QRadar Network Packet Capture 7.5.0 (base release)
  • IBM QRadar Network Packet Capture 7.5.0 update packages 1 through 7
  • Deployments exposing the management web interface to untrusted network segments

Discovery Timeline

  • 2024-08-15 - CVE-2024-31905 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-31905

Vulnerability Analysis

IBM QRadar Network Packet Capture 7.5 serves a management web interface over HTTPS but does not emit the Strict-Transport-Security response header. Without HSTS, browsers do not pin future connections to HTTPS and will accept redirects or initial requests over plain HTTP. An attacker on the same network path can use techniques such as SSL stripping, ARP spoofing, or rogue Wi-Fi access points to downgrade the client connection and relay traffic through a proxy. Captured material can include session cookies, administrative credentials, and packet metadata displayed in the console. The issue is a configuration and transport weakness rather than a memory-safety or injection flaw.

Root Cause

The root cause is a missing HTTP response header. The web server shipped with QRadar Network Packet Capture 7.5 does not set Strict-Transport-Security: max-age=<seconds>; includeSubDomains on authenticated or anonymous responses. Browsers therefore have no persisted directive to refuse plaintext HTTP to the host.

Attack Vector

Exploitation requires an attacker-in-the-middle position between an operator's browser and the QRadar appliance. The attacker intercepts the first HTTP request, prevents the HTTPS upgrade, and proxies the session. Because no HSTS policy is cached, the browser does not block the downgrade. Sensitive information transmitted during the session is then observable to the attacker. No vulnerability in the TLS stack itself is required.

See the IBM Support advisory for CVE-2024-31905 for vendor technical details.

Detection Methods for CVE-2024-31905

Indicators of Compromise

  • Unexpected ARP table changes or gratuitous ARP replies on management VLANs serving QRadar appliances
  • Administrator sessions to the packet capture console reaching the appliance over http:// rather than https://
  • TLS certificate warnings or certificate issuer mismatches reported by operators accessing the web interface
  • Authentication logs showing successful logins from unusual source IPs following suspected MITM activity

Detection Strategies

  • Scan the appliance with a TLS auditing tool and alert when the Strict-Transport-Security header is absent from HTTPS responses
  • Inspect network traffic on management segments for plaintext HTTP requests destined to QRadar packet capture appliances
  • Monitor for anomalies in DNS and ARP that indicate on-path interception on networks used for QRadar administration

Monitoring Recommendations

  • Capture and review web server access logs on the appliance for non-TLS requests and unexpected User-Agent strings
  • Alert on administrative logins originating from source addresses outside approved jump-host ranges
  • Track certificate presentation and TLS handshake failures reported by operator browsers connecting to the console

How to Mitigate CVE-2024-31905

Immediate Actions Required

  • Apply the fixed version referenced in the IBM Support advisory for QRadar Network Packet Capture 7.5
  • Restrict access to the packet capture management interface to a dedicated administrative VLAN or jump host
  • Require administrators to type the full https:// URL or use bookmarks that enforce TLS
  • Rotate credentials and session tokens used on the appliance if MITM activity is suspected

Patch Information

IBM published remediation guidance at the IBM Support page for CVE-2024-31905. Operators of QRadar Network Packet Capture 7.5.0 through update package 7 should upgrade to the version identified in that advisory, which enables HTTP Strict Transport Security on the management interface.

Workarounds

  • Place the appliance behind a reverse proxy that injects a Strict-Transport-Security header on all responses
  • Enforce HTTPS-only access through network ACLs that drop TCP/80 traffic to the appliance
  • Deploy browser-side policies, such as HSTS preload entries or managed browser configuration, that pin the appliance hostname to HTTPS
bash
# Example reverse proxy snippet to inject HSTS until the appliance is patched
# nginx configuration
server {
    listen 443 ssl;
    server_name qradar-pcap.example.internal;

    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;

    location / {
        proxy_pass https://qradar-pcap-backend;
        proxy_ssl_verify on;
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.