CVE-2016-9730: CSRF
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9730?
CVE-2016-9730 is classified as a medium severity vulnerability due to its potential for cross-site request forgery.
How do I fix CVE-2016-9730?
To fix CVE-2016-9730, apply the latest security patch provided by IBM for affected versions of QRadar Incident Forensics.
Which versions of IBM QRadar are affected by CVE-2016-9730?
CVE-2016-9730 affects IBM QRadar Incident Forensics versions 7.2.0 through 7.2.8 and QRadar Security Information and Event Manager versions 7.2.0 through 7.2.8.
What kind of attacks can CVE-2016-9730 enable?
CVE-2016-9730 can enable attackers to perform unauthorized actions as trusted users through cross-site request forgery.
Is there a workaround for CVE-2016-9730?
Currently, the recommended solution for CVE-2016-9730 is to apply the official patch from IBM, as there are no suggested workarounds.