Authorization Misconfiguration in IBM QRadar SIEM Affects Data Security
CVE-2016-2874
3.1LOW
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 30 November 2016
Summary
An authorization misconfiguration in IBM QRadar SIEM versions prior to MR2 Patch 13 for 7.1 and 7.2.7 for 7.2 allows remote authenticated users to gain unauthorized access to sensitive information through various unspecified vectors. This vulnerability poses a significant risk, as attackers could exploit it to facilitate data breaches or access confidential logs and reports.
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved