CVE-2014-3091: XSS
Published Oct 13, 2014
·Updated
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.1.x and 7.2.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
2 affected components
IBM QRadar Security Information and Event Manager=7.1.0
IBM QRadar Security Information and Event Manager=7.2.0
Event History
Oct 13, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3091?
CVE-2014-3091 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-3091?
To fix CVE-2014-3091, upgrade IBM QRadar SIEM to versions 7.2.0 or later that address the cross-site scripting issue.
3
What systems are affected by CVE-2014-3091?
CVE-2014-3091 affects IBM QRadar SIEM versions 7.1.x and 7.2.x.
4
Can CVE-2014-3091 be exploited remotely?
Yes, CVE-2014-3091 can be exploited remotely, allowing attackers to inject arbitrary scripts.
5
What type of attack does CVE-2014-3091 enable?
CVE-2014-3091 enables cross-site scripting (XSS) attacks through crafted URLs.