First published: Sun Oct 19 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4827 is classified as a medium severity vulnerability due to its potential for web-based attacks.
To fix CVE-2014-4827, upgrade your IBM QRadar Security Information and Event Manager to the latest patched version that mitigates this XSS vulnerability.
CVE-2014-4827 affects IBM Security QRadar SIEM versions 7.1 MR1 and 7.2 MR2.
CVE-2014-4827 is a cross-site scripting (XSS) vulnerability that allows remote script injections via crafted URLs.
Yes, CVE-2014-4827 can be exploited remotely by attackers using specially crafted URLs.