CVE-2016-2873: SQL Injection
Published Nov 30, 2016
·Updated
SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
8 affected components
IBM QRadar Security Information and Event Manager<=7.1.0
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
IBM QRadar Security Information and Event Manager=7.2.6
Remediation
Patch Available
Event History
Nov 30, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2873?
CVE-2016-2873 has been classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2016-2873?
To fix CVE-2016-2873, update your IBM QRadar SIEM to version 7.2.7 or apply the specific patches to the earlier versions mentioned.
3
Who is affected by CVE-2016-2873?
CVE-2016-2873 affects authenticated users of IBM QRadar SIEM versions 7.1 before MR2 Patch 13 and 7.2 before 7.2.7.
4
What type of vulnerability is CVE-2016-2873?
CVE-2016-2873 is an SQL injection vulnerability that enables remote authenticated users to execute arbitrary SQL commands.
5
When was CVE-2016-2873 discovered?
CVE-2016-2873 was publicly disclosed in April 2016.