CVE-2016-2872: Path Traversal
Published Jul 2, 2016
·Updated
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
Affected Software
14 affected components
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
IBM QRadar Security Information and Event Manager=7.2.6
IBM Security QRadar Incident Forensics=7.2.0
IBM Security QRadar Incident Forensics=7.2.1
IBM Security QRadar Incident Forensics=7.2.2
IBM Security QRadar Incident Forensics=7.2.3
IBM Security QRadar Incident Forensics=7.2.4
IBM Security QRadar Incident Forensics=7.2.5
IBM Security QRadar Incident Forensics=7.2.6
Event History
Jul 2, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2872?
CVE-2016-2872 is rated as a medium severity vulnerability, allowing unauthorized file access.
2
How do I fix CVE-2016-2872?
To fix CVE-2016-2872, upgrade to IBM Security QRadar SIEM version 7.2.7 or later.
3
Which versions of IBM Security QRadar are affected by CVE-2016-2872?
CVE-2016-2872 affects IBM Security QRadar SIEM versions 7.2.0 through 7.2.6 and QRadar Incident Forensics versions 7.2.0 through 7.2.6.
4
Can CVE-2016-2872 be exploited remotely?
Yes, CVE-2016-2872 can be exploited remotely via crafted URLs by attackers.
5
What impact does CVE-2016-2872 have on systems?
CVE-2016-2872 allows attackers to read arbitrary files on the affected systems, potentially leading to sensitive information disclosure.