First published: Mon Feb 15 2016(Updated: )
The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4956 is classified as a moderate to high severity vulnerability due to the potential for remote command execution by authenticated users.
To fix CVE-2015-4956, upgrade to IBM Security QRadar SIEM version 7.1 MR2 Patch 12 or later.
CVE-2015-4956 affects users of IBM Security QRadar SIEM version 7.1.x prior to 7.1 MR2 Patch 12.
Exploitation of CVE-2015-4956 could allow authenticated users to execute arbitrary OS commands on the vulnerable system.
CVE-2015-4956 was published in July 2015.