Cross-Site Scripting Vulnerability in IBM QRadar Advisor
CVE-2021-38896
6.1MEDIUM
Summary
The IBM QRadar Advisor products ranging from version 2.5 to 2.6.1 are susceptible to a cross-site scripting vulnerability. This issue enables malicious actors to inject arbitrary JavaScript code into the application’s Web UI, compromising the integrity of the trusted session. As a result, sensitive information such as user credentials may be exposed. This vulnerability can significantly impact users and the overall security posture of affected systems.
Affected Version(s)
Qradar Advisor 2.5
Qradar Advisor 2.6.1
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved