Command Injection Vulnerability in IBM QRadar SIEM
CVE-2016-2876
7.5HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 30 November 2016
Summary
A command injection vulnerability exists in IBM QRadar SIEM versions prior to MR2 Patch 13 for 7.1 and versions prior to 7.2.7. This weakness allows remote authenticated users to exploit the system by executing processes at elevated privilege levels. By leveraging this flaw, attackers can potentially gain unauthorized root access, compromising the integrity and security of the affected system.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved