CVE-2015-1919: XSS
Published Jun 30, 2015
·Updated
Cross-site scripting (XSS) vulnerability in IBM Security QRadar Incident Forensics before 7.2.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
1 affected component
IBM Security QRadar Incident Forensics<=7.2.4
Event History
Jun 30, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1919?
CVE-2015-1919 has a medium severity rating due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2015-1919?
To fix CVE-2015-1919, upgrade to IBM Security QRadar Incident Forensics version 7.2.5 or later.
3
What types of attacks can CVE-2015-1919 enable?
CVE-2015-1919 can enable remote attackers to execute arbitrary web scripts or inject HTML through crafted URLs.
4
What software is affected by CVE-2015-1919?
CVE-2015-1919 affects IBM Security QRadar Incident Forensics versions prior to 7.2.5.
5
Who can exploit CVE-2015-1919?
Remote attackers can exploit CVE-2015-1919 to perform cross-site scripting attacks on vulnerable installations.