CVE-2015-4957: XSS
Published Feb 15, 2016
·Updated
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
1 affected component
IBM QRadar Security Information and Event Manager=7.1.0
Event History
Feb 15, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4957?
CVE-2015-4957 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
2
Who is affected by CVE-2015-4957?
CVE-2015-4957 affects users of IBM Security QRadar SIEM versions 7.1.x before 7.1 MR2 Patch 12.
3
How do I fix CVE-2015-4957?
To fix CVE-2015-4957, update to IBM Security QRadar SIEM version 7.1 MR2 Patch 12 or later.
4
What type of vulnerability is CVE-2015-4957?
CVE-2015-4957 is a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2015-4957 be exploited remotely?
Yes, CVE-2015-4957 can be exploited by remote authenticated users through a crafted URL.