Command Injection Vulnerability in IBM QRadar SIEM
CVE-2016-2876

7.5HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
30 November 2016

Summary

A command injection vulnerability exists in IBM QRadar SIEM versions prior to MR2 Patch 13 for 7.1 and versions prior to 7.2.7. This weakness allows remote authenticated users to exploit the system by executing processes at elevated privilege levels. By leveraging this flaw, attackers can potentially gain unauthorized root access, compromising the integrity and security of the affected system.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.