CVE-2015-4956: OS Command Injection
Published Feb 15, 2016
·Updated
The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown vectors.
Affected Software
1 affected component
IBM QRadar Security Information and Event Manager=7.1.0
Event History
Feb 15, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4956?
CVE-2015-4956 is classified as a moderate to high severity vulnerability due to the potential for remote command execution by authenticated users.
2
How do I fix CVE-2015-4956?
To fix CVE-2015-4956, upgrade to IBM Security QRadar SIEM version 7.1 MR2 Patch 12 or later.
3
Who is affected by CVE-2015-4956?
CVE-2015-4956 affects users of IBM Security QRadar SIEM version 7.1.x prior to 7.1 MR2 Patch 12.
4
What are the consequences of CVE-2015-4956 exploitation?
Exploitation of CVE-2015-4956 could allow authenticated users to execute arbitrary OS commands on the vulnerable system.
5
When was CVE-2015-4956 published?
CVE-2015-4956 was published in July 2015.