CVE-2019-4211: XSS
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4211?
CVE-2019-4211 has been rated as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2019-4211?
To mitigate CVE-2019-4211, it is recommended to update IBM QRadar SIEM to the latest version beyond 7.2.8.15 or 7.3.2.
What software versions are affected by CVE-2019-4211?
CVE-2019-4211 affects IBM QRadar SIEM versions 7.2.0 to 7.2.8.15 and 7.3.0 to 7.3.2.
What type of attack does CVE-2019-4211 enable?
CVE-2019-4211 enables cross-site scripting attacks that can lead to unauthorized execution of JavaScript in a user's browser.
Who is responsible for addressing CVE-2019-4211?
The responsibility for addressing CVE-2019-4211 lies with the administrators of affected IBM QRadar SIEM installations.