CVE-2016-2876: OS Command Injection
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2876?
CVE-2016-2876 has a high severity rating due to the potential for remote authenticated users to gain root access.
How do I fix CVE-2016-2876?
To fix CVE-2016-2876, users should upgrade to IBM QRadar SIEM version 7.1 MR2 Patch 13 or version 7.2.7 or newer.
Which versions of IBM QRadar SIEM are affected by CVE-2016-2876?
Affected versions of IBM QRadar SIEM include 7.1 before MR2 Patch 13 and 7.2 versions prior to 7.2.7.
What causes the vulnerability in CVE-2016-2876?
The vulnerability in CVE-2016-2876 is caused by unspecified processes executing at an incorrect privilege level due to a command-injection issue.
Who is at risk due to CVE-2016-2876?
Remote authenticated users with access to vulnerable versions of IBM QRadar SIEM are at risk of obtaining root access.