CVE-2016-9722: Medium severity ibm qradar security information and event manager vulnerability
Published Jan 10, 2018
·Updated
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.
Affected Software
10 affected components
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
IBM QRadar Security Information and Event Manager=7.2.6
IBM QRadar Security Information and Event Manager=7.2.7
IBM QRadar Security Information and Event Manager=7.2.8
IBM QRadar Security Information and Event Manager=7.3.0
Event History
Jan 10, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9722?
CVE-2016-9722 is classified as a medium severity vulnerability due to improper permissions that may allow unauthorized access.
2
How do I fix CVE-2016-9722?
To fix CVE-2016-9722, update IBM QRadar Security Information and Event Manager to the latest available version that includes the security patch.
3
What versions of IBM QRadar are affected by CVE-2016-9722?
CVE-2016-9722 affects IBM QRadar versions 7.2.0 through 7.3.0.
4
What type of access does CVE-2016-9722 allow?
CVE-2016-9722 allows unauthorized actors to read or modify security-critical resources.
5
Is there a workaround for CVE-2016-9722?
There are no widely recommended workarounds for CVE-2016-9722; applying the security update is the advised method for mitigation.