Cross-Site Scripting Vulnerabilities in IBM QRadar SIEM
CVE-2016-2869

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
30 November 2016

Summary

Multiple cross-site scripting (XSS) vulnerabilities exist in the user interface of IBM QRadar SIEM versions prior to specified patches. These vulnerabilities allow remote authenticated users to exploit the system by injecting arbitrary web scripts or HTML through specially crafted URLs, undermining the security of the application and potentially leading to unauthorized actions within the platform.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.