CVE-2016-9728: SQL Injection
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9728?
CVE-2016-9728 has a medium severity rating, indicating a moderate potential impact on affected systems.
How do I fix CVE-2016-9728?
To fix CVE-2016-9728, upgrade IBM QRadar Security Information and Event Manager to the latest version, which addresses the SQL injection vulnerability.
What versions of IBM QRadar are affected by CVE-2016-9728?
Versions 7.2.0 through 7.2.8 of IBM QRadar Security Information and Event Manager are affected by CVE-2016-9728.
What type of vulnerability is CVE-2016-9728?
CVE-2016-9728 is a SQL injection vulnerability that could allow remote attackers to access the back-end database.
Can the exploitation of CVE-2016-9728 lead to unauthorized access?
Yes, successful exploitation of CVE-2016-9728 can allow attackers to view sensitive information stored in the database.