First published: Tue Mar 26 2024(Updated: )
IBM QRadar is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security QRadar | <=7.5 - 7.5.0 UP7 IF06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50960 has a moderate severity rating due to its potential impact on user sessions and credential disclosure.
To fix CVE-2023-50960, ensure that you update your IBM QRadar SIEM to the latest version beyond 7.5 - 7.5.0 UP7 IF06.
CVE-2023-50960 affects users of IBM QRadar SIEM versions 7.5 - 7.5.0 UP7 IF06 and earlier.
Stored cross-site scripting in CVE-2023-50960 allows attackers to inject malicious JavaScript code into the web interface of QRadar.
The potential impacts of CVE-2023-50960 include unauthorized actions taken on behalf of the user and possible credential theft.