First published: Sun Oct 04 2015(Updated: )
Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unknown vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2016 is considered a high severity vulnerability due to the potential for remote code execution with root privileges.
To fix CVE-2015-2016, upgrade IBM QRadar SIEM to version 7.1 MR2 Patch 11 IF02 or version 7.2.x to 7.2.5 Patch 4 or later.
CVE-2015-2016 affects authenticated remote users of IBM QRadar SIEM versions 7.1 MR2 before Patch 11 IF02 and 7.2.0 through 7.2.4.
CVE-2015-2016 can enable remote authenticated users to execute arbitrary commands on the affected system.
There is no documented workaround for CVE-2015-2016; applying the patch is the recommended solution.