First published: Wed Nov 30 2016(Updated: )
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended access restrictions via modified request parameters.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | <=7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.2.5 | |
IBM QRadar Security Information and Event Manager | =7.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2881 is classified as a medium severity vulnerability.
To fix CVE-2016-2881, ensure you update IBM QRadar SIEM to the latest version available, specifically 7.1 MR2 Patch 13 or 7.2.7 and above.
CVE-2016-2881 affects IBM QRadar SIEM versions before 7.1 MR2 Patch 13 and all versions prior to 7.2.7.
CVE-2016-2881 allows remote attackers to bypass access restrictions, potentially compromising sensitive data.
CVE-2016-2881 has been reported as being actively exploited, so it is crucial to apply the updates promptly.