First published: Mon Oct 13 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.1.x and 7.2.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3091 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-3091, upgrade IBM QRadar SIEM to versions 7.2.0 or later that address the cross-site scripting issue.
CVE-2014-3091 affects IBM QRadar SIEM versions 7.1.x and 7.2.x.
Yes, CVE-2014-3091 can be exploited remotely, allowing attackers to inject arbitrary scripts.
CVE-2014-3091 enables cross-site scripting (XSS) attacks through crafted URLs.