CVE-2014-0836: XSS
Published Jan 30, 2014
·Updated
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
1 affected component
IBM QRadar Security Information and Event Manager<=7.2.0
Event History
Jan 30, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·05:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0836?
CVE-2014-0836 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-0836?
To fix CVE-2014-0836, upgrade your IBM Security QRadar SIEM to a version later than 7.2 MR1.
3
What type of vulnerability is CVE-2014-0836?
CVE-2014-0836 is a cross-site scripting (XSS) vulnerability.
4
What versions of IBM QRadar Security Information and Event Manager are affected by CVE-2014-0836?
CVE-2014-0836 affects IBM QRadar Security Information and Event Manager versions 7.2 MR1 and earlier.
5
Can CVE-2014-0836 be exploited remotely?
Yes, CVE-2014-0836 can be exploited remotely by attackers through crafted URLs.