Cross-Site Scripting Vulnerability in IBM QRadar Advisor
CVE-2021-38896

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 October 2021

Summary

The IBM QRadar Advisor products ranging from version 2.5 to 2.6.1 are susceptible to a cross-site scripting vulnerability. This issue enables malicious actors to inject arbitrary JavaScript code into the application’s Web UI, compromising the integrity of the trusted session. As a result, sensitive information such as user credentials may be exposed. This vulnerability can significantly impact users and the overall security posture of affected systems.

Affected Version(s)

Qradar Advisor 2.5

Qradar Advisor 2.6.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.