First published: Tue Mar 07 2017(Updated: )
IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM Reference #: 1999545.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.2.5 | |
IBM QRadar Security Information and Event Manager | =7.2.6 | |
IBM QRadar Security Information and Event Manager | =7.2.7 | |
IBM QRadar Security Information and Event Manager | =7.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9729 is considered a critical vulnerability due to the lack of authentication checks allowing unauthorized access.
To fix CVE-2016-9729, apply the latest patches provided by IBM for affected versions of QRadar.
CVE-2016-9729 affects IBM QRadar versions 7.2.0 through 7.2.8.
CVE-2016-9729 allows anonymous users to access protected areas, potentially leading to data breaches or unauthorized information exposure.
Currently, the best approach is to upgrade to the latest version of IBM QRadar to mitigate the risks associated with CVE-2016-9729.