CVE-2023-47731: IBM QRadar Suite Software cross-site scripting
IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 272203.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47731?
CVE-2023-47731 has been classified as a moderate severity vulnerability due to its potential to allow execution of arbitrary JavaScript code in the Web UI.
How do I fix CVE-2023-47731?
To fix CVE-2023-47731, upgrade your IBM QRadar Suite Software to version 1.10.20.0 or later, or your IBM Cloud Pak for Security to version 1.10.12.0 or later.
Who is affected by CVE-2023-47731?
CVE-2023-47731 affects users of IBM QRadar Suite Software versions 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
What does CVE-2023-47731 allow an attacker to do?
CVE-2023-47731 allows an attacker to embed arbitrary JavaScript code in the Web UI, potentially altering functionality or compromising data.
Is CVE-2023-47731 a cross-site scripting vulnerability?
Yes, CVE-2023-47731 is categorized as a stored cross-site scripting (XSS) vulnerability.