CVE-2014-4827: XSS
Published Oct 19, 2014
·Updated
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
2 affected components
IBM QRadar Security Information and Event Manager=7.1.0
IBM QRadar Security Information and Event Manager=7.2.0
Event History
Oct 19, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4827?
CVE-2014-4827 is classified as a medium severity vulnerability due to its potential for web-based attacks.
2
How do I fix CVE-2014-4827?
To fix CVE-2014-4827, upgrade your IBM QRadar Security Information and Event Manager to the latest patched version that mitigates this XSS vulnerability.
3
Who is affected by CVE-2014-4827?
CVE-2014-4827 affects IBM Security QRadar SIEM versions 7.1 MR1 and 7.2 MR2.
4
What type of vulnerability is CVE-2014-4827?
CVE-2014-4827 is a cross-site scripting (XSS) vulnerability that allows remote script injections via crafted URLs.
5
Can CVE-2014-4827 be exploited remotely?
Yes, CVE-2014-4827 can be exploited remotely by attackers using specially crafted URLs.