First published: Wed Nov 30 2016(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authenticated users to inject arbitrary web script or HTML via crafted fields in a URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | <=7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.2.5 | |
IBM QRadar Security Information and Event Manager | =7.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2869 has a medium severity level due to multiple cross-site scripting vulnerabilities.
To fix CVE-2016-2869, update IBM QRadar SIEM to version 7.1 MR2 Patch 13 or 7.2.7 or later.
CVE-2016-2869 affects IBM QRadar SIEM versions 7.1 before MR2 Patch 13 and 7.2 before 7.2.7.
CVE-2016-2869 allows remote authenticated users to inject arbitrary web scripts or HTML, leading to potential XSS attacks.
Yes, CVE-2016-2869 has been patched in later versions of IBM QRadar SIEM.