CVE-2013-5463: Medium severity ibm qradar security information and event manager vulnerability
Published Nov 29, 2013
·Updated
The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file.
Affected Software
3 affected components
IBM QRadar Security Information and Event Manager<=7.1.0
IBM QRadar Security Information and Event Manager=7.0.0
IBM QRadar Security Information and Event Manager=7.0.1
Event History
Nov 29, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5463?
CVE-2013-5463 is considered to have a medium severity due to its potential for remote code execution.
2
How do I fix CVE-2013-5463?
To fix CVE-2013-5463, upgrade the IBM Security QRadar SIEM to the version 7.1.1.569824 or later.
3
Who is affected by CVE-2013-5463?
Organizations using IBM Security QRadar SIEM versions 7.0.0, 7.0.1, or before 7.1.1.569824 are affected by CVE-2013-5463.
4
What types of attacks can exploit CVE-2013-5463?
CVE-2013-5463 can be exploited for DLL injection or manipulation of configuration files, allowing unauthorized access.
5
When was CVE-2013-5463 disclosed?
CVE-2013-5463 was publicly disclosed in 2013.