CVE-2019-4581: XSS
Published Nov 5, 2019
·Updated
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 167239.
Affected Software
6 affected components
IBM QRadar Security Information and Event Manager>=7.3.0<=7.3.1
IBM QRadar Security Information and Event Manager=7.3.2
IBM QRadar Security Information and Event Manager=7.3.2-p1
IBM QRadar Security Information and Event Manager=7.3.2-p2
IBM QRadar Security Information and Event Manager=7.3.2-p3
IBM QRadar Security Information and Event Manager=7.3.2-p4
Remediation
Patch Available
Event History
Nov 5, 2019
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
SeverityAffected Software
Nov 9, 2019
CVE Published
via MITRE·01:41 AM
Data Sourced
via MITRE·01:41 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4581?
CVE-2019-4581 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2019-4581?
To fix CVE-2019-4581, update IBM QRadar to version 7.3.2 Patch 5 or later.
3
What are the affected versions in CVE-2019-4581?
CVE-2019-4581 affects IBM QRadar versions 7.3.0 to 7.3.2 Patch 4.
4
What type of vulnerability is CVE-2019-4581?
CVE-2019-4581 is a cross-site scripting vulnerability allowing for arbitrary JavaScript code to be embedded.
5
What can be the potential impact of CVE-2019-4581?
The potential impact of CVE-2019-4581 includes credential disclosure within a trusted session.