CVE-2016-2874: Low severity ibm qradar security information and event manager vulnerability
Published Nov 30, 2016
·Updated
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Affected Software
8 affected components
IBM QRadar Security Information and Event Manager<=7.1.0
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
IBM QRadar Security Information and Event Manager=7.2.6
Remediation
Patch Available
Event History
Nov 30, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2874?
CVE-2016-2874 has a medium severity rating as it allows remote authenticated users to access sensitive information.
2
How do I fix CVE-2016-2874?
To fix CVE-2016-2874, apply MR2 Patch 13 for version 7.1 and update to version 7.2.7 or later.
3
Which versions of IBM QRadar Security Information and Event Manager are affected by CVE-2016-2874?
CVE-2016-2874 affects IBM QRadar SIEM versions 7.1 before MR2 Patch 13 and 7.2 before 7.2.7.
4
Who can exploit the CVE-2016-2874 vulnerability?
CVE-2016-2874 can be exploited by remote authenticated users who have access to the affected IBM QRadar SIEM versions.
5
What type of information can be exposed due to CVE-2016-2874?
CVE-2016-2874 can potentially expose sensitive information due to mishandled authorization in the IBM QRadar SIEM.