CVE-2022-22320: XSS
IBM QRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218367.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22320?
CVE-2022-22320 is a vulnerability in IBM QRadar SIEM that allows for cross-site scripting, potentially leading to credentials disclosure.
How does CVE-2022-22320 affect IBM QRadar SIEM?
CVE-2022-22320 allows users to embed arbitrary JavaScript code in the Web UI of IBM QRadar SIEM, altering the intended functionality.
What is the severity of CVE-2022-22320?
CVE-2022-22320 has a severity rating of medium with a CVSS score of 4.8.
Which versions of IBM QRadar SIEM are affected by CVE-2022-22320?
IBM QRadar SIEM 7.3.3 and 7.4.3, as well as their respective fix packs, are affected by CVE-2022-22320.
How can I fix CVE-2022-22320 in IBM QRadar SIEM?
To fix CVE-2022-22320 in IBM QRadar SIEM, you should apply the appropriate patches provided by IBM.