CVE-2015-5044: Input Validation
Published Nov 8, 2015
·Updated
The Flow Collector in IBM Security QRadar QFLOW 7.1.x before 7.1 MR2 Patch 11 IF3 and 7.2.x before 7.2.5 Patch 4 IF3 allows remote attackers to cause a denial of service via unspecified packets.
Affected Software
9 affected components
IBM QRadar Security Information and Event Manager=7.0.0
IBM QRadar Security Information and Event Manager=7.0.1
IBM QRadar Security Information and Event Manager=7.1.0
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
Event History
Nov 8, 2015
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5044?
CVE-2015-5044 has a high severity rating as it allows remote attackers to cause a denial of service.
2
How do I fix CVE-2015-5044?
To fix CVE-2015-5044, update to IBM Security QRadar QFLOW version 7.1 MR2 Patch 11 IF3 or 7.2.5 Patch 4 IF3.
3
Which versions of IBM QRadar are affected by CVE-2015-5044?
CVE-2015-5044 affects IBM QRadar versions 7.0.0, 7.0.1, 7.1.0, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, and 7.2.5 before the specified patches.
4
What type of vulnerability is CVE-2015-5044?
CVE-2015-5044 is a denial of service vulnerability.
5
Are there any workarounds for CVE-2015-5044?
There are no specific workarounds for CVE-2015-5044; applying the patches is the recommended solution.