CVE-2016-9725: Infoleak
Published Mar 7, 2017
·Updated
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate them. IBM Reference #: 1999539.
Affected Software
9 affected components
IBM QRadar Security Information and Event Manager=7.2.0
IBM QRadar Security Information and Event Manager=7.2.1
IBM QRadar Security Information and Event Manager=7.2.2
IBM QRadar Security Information and Event Manager=7.2.3
IBM QRadar Security Information and Event Manager=7.2.4
IBM QRadar Security Information and Event Manager=7.2.5
IBM QRadar Security Information and Event Manager=7.2.6
IBM QRadar Security Information and Event Manager=7.2.7
IBM QRadar Security Information and Event Manager=7.2.8
Remediation
Patch Available
Event History
Mar 7, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9725?
CVE-2016-9725 has a high severity rating due to its potential for exploitation via Cross-Origin Resource Sharing.
2
How do I fix CVE-2016-9725?
To fix CVE-2016-9725, apply the recommended patches provided by IBM for affected versions of QRadar.
3
Which versions of IBM QRadar are affected by CVE-2016-9725?
CVE-2016-9725 affects IBM QRadar Incident Forensics versions 7.2.0 through 7.2.8.
4
What type of vulnerability is CVE-2016-9725?
CVE-2016-9725 is a Cross-Origin Resource Sharing (CORS) vulnerability that can allow unauthorized access to resources.
5
Is CVE-2016-9725 remotely exploitable?
Yes, CVE-2016-9725 can be remotely exploited, posing a risk to vulnerable systems.