CVE-2023-26274: IBM QRadar cross-site scripting
IBM QRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM QRadar vulnerability?
The vulnerability ID for this IBM QRadar vulnerability is CVE-2023-26274.
What is the severity level of CVE-2023-26274?
The severity level of CVE-2023-26274 is medium.
What is the affected version of IBM QRadar SIEM?
The affected version of IBM QRadar SIEM is 7.5.0.
How does this vulnerability affect IBM QRadar SIEM?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI of IBM QRadar SIEM 7.5.0, potentially leading to credentials disclosure within a trusted session.
Is Linux Linux kernel affected by this vulnerability?
No, Linux Linux kernel is not affected by this vulnerability.