CVE-2019-4470: XSS
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163779.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4470?
CVE-2019-4470 has a medium severity rating due to its potential to lead to credentials disclosure through cross-site scripting.
How do I fix CVE-2019-4470?
To fix CVE-2019-4470, users should apply the latest patches available for IBM QRadar Security Information and Event Manager.
Who is affected by CVE-2019-4470?
CVE-2019-4470 affects users of IBM QRadar Security Information and Event Manager versions 7.3.0 to 7.3.2 Patch 4.
What type of vulnerability is CVE-2019-4470?
CVE-2019-4470 is a cross-site scripting vulnerability, allowing the injection of arbitrary JavaScript code.
Can CVE-2019-4470 lead to data breaches?
Yes, CVE-2019-4470 can potentially lead to data breaches by exposing credentials within trusted sessions.