IBM QRadar EDR Vulnerable to HTML Injection
CVE-2023-35006
5.4MEDIUM
Summary
IBM Security QRadar EDR 3.12 is affected by a vulnerability that permits HTML injection. This flaw enables a remote attacker to sneak malicious HTML code into the web interface. When this compromised code is rendered in the browser of a user with access to the hosting site, it executes under the site's security context, potentially leading to unauthorized actions or data exposure. The vulnerability raises significant concerns regarding web application security, as it could facilitate a range of malicious activities if not properly mitigated. For more details on the potential implications and security measures, visit the official IBM advisory and vulnerability database.
Affected Version(s)
Security QRadar EDR 3.12
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved