CVE-2020-4268: XSS
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 175841.
Other sources
IBM QRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM QRadar vulnerability?
The vulnerability ID is CVE-2020-4268.
What is the severity rating of CVE-2020-4268?
The severity rating of CVE-2020-4268 is medium.
How does CVE-2020-4268 affect IBM QRadar?
CVE-2020-4268 affects IBM QRadar versions 7.3.0 to 7.3.3 Patch 2.
What is the impact of CVE-2020-4268?
The impact of CVE-2020-4268 is that it allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Is there a fix available for CVE-2020-4268?
Yes, IBM has released patches to fix the vulnerability. It is recommended to update to IBM QRadar versions 7.3.3 Patch 3 or higher.