First published: Tue Mar 07 2017(Updated: )
IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.2.5 | |
IBM QRadar Security Information and Event Manager | =7.2.6 | |
IBM QRadar Security Information and Event Manager | =7.2.7 | |
IBM QRadar Security Information and Event Manager | =7.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9740 is considered a high-severity vulnerability due to its potential to allow remote attackers to consume server resources.
CVE-2016-9740 affects IBM QRadar Security Information and Event Manager versions 7.2.0 to 7.2.8.
To mitigate CVE-2016-9740, users should apply the latest security patches provided by IBM for the affected QRadar versions.
Yes, CVE-2016-9740 can be exploited remotely, allowing attackers to send requests that consume all resources.
Currently, the best mitigation is to apply the available patches, as workarounds may not fully protect against the vulnerability.