CVE-2023-47727: IBM QRadar Suite Software file manipulation
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089.
Other sources
IBM QRadar Suite Software could allow an authenticated user to modify dashboard parameters due to improper input validation.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47727?
CVE-2023-47727 is considered a medium severity vulnerability due to improper input validation allowing authenticated users to modify dashboard parameters.
How do I fix CVE-2023-47727?
To fix CVE-2023-47727, update IBM Cloud Pak for Security to version 1.10.11.1 or later and IBM QRadar Suite Software to version 1.10.20.1 or later.
Who is affected by CVE-2023-47727?
CVE-2023-47727 affects users of IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software versions 1.10.12.0 through 1.10.20.0.
What type of attack can exploit CVE-2023-47727?
CVE-2023-47727 can be exploited by an authenticated user to manipulate dashboard parameters due to improper input validation.
Is there a workaround for CVE-2023-47727?
There are currently no documented workarounds for CVE-2023-47727; updating the software is the recommended solution.