CVE-2023-50960: Medium severity ibm security qradar vulnerability
IBM QRadar is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50960?
CVE-2023-50960 has a moderate severity rating due to its potential impact on user sessions and credential disclosure.
How do I fix CVE-2023-50960?
To fix CVE-2023-50960, ensure that you update your IBM QRadar SIEM to the latest version beyond 7.5 - 7.5.0 UP7 IF06.
Who is affected by CVE-2023-50960?
CVE-2023-50960 affects users of IBM QRadar SIEM versions 7.5 - 7.5.0 UP7 IF06 and earlier.
What is stored cross-site scripting in CVE-2023-50960?
Stored cross-site scripting in CVE-2023-50960 allows attackers to inject malicious JavaScript code into the web interface of QRadar.
What are the potential impacts of CVE-2023-50960?
The potential impacts of CVE-2023-50960 include unauthorized actions taken on behalf of the user and possible credential theft.