First published: Thu Mar 29 2018(Updated: )
Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force ID: 103921.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.2.0<7.2.5 | |
IBM QRadar Security Information and Event Manager | =7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.1.0-mr1 | |
IBM QRadar Security Information and Event Manager | =7.1.0-mr2 | |
IBM QRadar Security Information and Event Manager | =7.2.5-patch1 | |
IBM QRadar Security Information and Event Manager | =7.2.5-patch2 | |
IBM QRadar Security Information and Event Manager | =7.2.5-patch3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.