CVE-2013-2970: Medium severity IBM QRadar Security Information and Event Manager vulnerability
Published Jun 3, 2013
·Updated
Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to execute operating-system commands via unknown vectors.
Affected Software
3 affected components
IBM QRadar Security Information and Event Manager=7.0.0
IBM QRadar Security Information and Event Manager=7.0.1
IBM QRadar Security Information and Event Manager=7.1.0
Event History
Jun 3, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2970?
CVE-2013-2970 is considered a critical vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2013-2970?
To mitigate CVE-2013-2970, update IBM QRadar Security Information and Event Manager to version 7.1 MR2 Patch 1 or later.
3
What versions of IBM QRadar are affected by CVE-2013-2970?
CVE-2013-2970 affects IBM QRadar versions 7.0.0, 7.0.1, and 7.1.0.
4
Can CVE-2013-2970 be exploited by unauthenticated users?
No, CVE-2013-2970 requires remote authenticated users for exploitation.
5
What type of attack is possible due to CVE-2013-2970?
CVE-2013-2970 allows authenticated users to execute arbitrary operating-system commands.