Cross-Site Request Forgery Vulnerability in IBM QRadar User Behavior Analytics
CVE-2021-29757
4.3MEDIUM
Summary
IBM QRadar User Behavior Analytics version 4.1.1 is susceptible to a Cross-Site Request Forgery attack, which can enable an attacker to execute unauthorized actions on behalf of a trusted user. This vulnerability arises from improper validation of requests, allowing the potential for malicious actions to be carried out without the knowledge of the user. Organizations utilizing this product should implement mitigation strategies to protect against unauthorized access and ensure that sensitive operations are secured.
Affected Version(s)
QRadar User Behavior Analytics 4.1.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved