First published: Sun Nov 08 2015(Updated: )
SQL injection vulnerability in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Incident Forensics | =7.2.0 | |
IBM QRadar Incident Forensics | =7.2.1 | |
IBM QRadar Incident Forensics | =7.2.2 | |
IBM QRadar Incident Forensics | =7.2.3 | |
IBM QRadar Incident Forensics | =7.2.4 | |
IBM QRadar Incident Forensics | =7.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1989 is rated as a medium severity vulnerability due to its potential impact on database security.
To mitigate CVE-2015-1989, upgrade IBM Security QRadar Incident Forensics to version 7.2.5 Patch 5 or later.
Versions 7.2.0 to 7.2.4 of IBM Security QRadar Incident Forensics are affected by CVE-2015-1989.
CVE-2015-1989 is an SQL injection vulnerability that allows remote authenticated users to execute arbitrary SQL commands.
If you are using an affected version, you should promptly apply the available patches to prevent exploitation of CVE-2015-1989.