First published: Tue Mar 07 2017(Updated: )
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.2.5 | |
IBM QRadar Security Information and Event Manager | =7.2.6 | |
IBM QRadar Security Information and Event Manager | =7.2.7 | |
IBM QRadar Security Information and Event Manager | =7.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9728 has a medium severity rating, indicating a moderate potential impact on affected systems.
To fix CVE-2016-9728, upgrade IBM QRadar Security Information and Event Manager to the latest version, which addresses the SQL injection vulnerability.
Versions 7.2.0 through 7.2.8 of IBM QRadar Security Information and Event Manager are affected by CVE-2016-9728.
CVE-2016-9728 is a SQL injection vulnerability that could allow remote attackers to access the back-end database.
Yes, successful exploitation of CVE-2016-9728 can allow attackers to view sensitive information stored in the database.