Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2016-9723

Disclosure Date: March 07, 2017 (last updated November 26, 2024)
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
0
Attacker Value
Unknown

CVE-2016-9727

Disclosure Date: March 07, 2017 (last updated November 26, 2024)
IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.
0
Attacker Value
Unknown

CVE-2016-9720

Disclosure Date: March 07, 2017 (last updated November 26, 2024)
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.
0
Attacker Value
Unknown

CVE-2017-1133

Disclosure Date: March 07, 2017 (last updated November 26, 2024)
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
0
Attacker Value
Unknown

CVE-2016-9726

Disclosure Date: March 07, 2017 (last updated November 26, 2024)
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.
0
Attacker Value
Unknown

CVE-2016-9730

Disclosure Date: March 07, 2017 (last updated November 26, 2024)
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.
0
Attacker Value
Unknown

CVE-2016-2968

Disclosure Date: July 02, 2016 (last updated November 25, 2024)
IBM Security QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to bypass authentication, and obtain sensitive information or modify data, via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-2872

Disclosure Date: July 02, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
0
Attacker Value
Unknown

CVE-2015-1999

Disclosure Date: November 08, 2015 (last updated October 05, 2023)
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
0
Attacker Value
Unknown

CVE-2015-1996

Disclosure Date: November 08, 2015 (last updated October 05, 2023)
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.
0