CVE-2016-2875: Command Injection
Published Aug 8, 2016
·Updated
IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vectors.
Affected Software
8 affected components
IBM QRadar Security Information and Event Manager=7.1.0
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
IBM QRadar Security Information and Event Manager=7.2.6
Remediation
Patch Available
Event History
Aug 8, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2875?
The severity of CVE-2016-2875 is considered high due to the ability of remote authenticated users to execute arbitrary OS commands as root.
2
How do I fix CVE-2016-2875?
To fix CVE-2016-2875, upgrade IBM QRadar SIEM to version 7.2.7 or later.
3
Who is affected by CVE-2016-2875?
CVE-2016-2875 affects IBM Security QRadar SIEM versions 7.1.x and 7.2.x before 7.2.7.
4
What type of attack is CVE-2016-2875 associated with?
CVE-2016-2875 is associated with remote command execution attacks.
5
Is authentication required to exploit CVE-2016-2875?
Yes, exploitation of CVE-2016-2875 requires the attacker to be a remote authenticated user.