First published: Mon Jul 08 2024(Updated: )
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 297165.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security QRadar EDR | <=3.12 | |
IBM Security QRadar EDR | =3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35006 is categorized as a high severity vulnerability due to the potential for HTML injection attacks.
To fix CVE-2023-35006, upgrade IBM Security QRadar EDR to a version that is not affected by this vulnerability.
CVE-2023-35006 affects users of IBM Security QRadar EDR version 3.12.
CVE-2023-35006 can be exploited through HTML injection, allowing attackers to execute malicious code in a victim's browser.
To mitigate CVE-2023-35006, implement input validation and output encoding practices to prevent HTML injection.