Lucene search

K
cveIbmCVE-2014-0838
HistoryJan 30, 2014 - 5:17 a.m.

CVE-2014-0838

2014-01-3005:17:46
ibm
web.nvd.nist.gov
23
cve-2014-0838
autoupdate package
ibm security qradar siem
remote attackers
arbitrary console commands
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.006

Percentile

79.2%

The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute arbitrary console commands by leveraging control of the server.

Affected configurations

Nvd
Node
ibmqradar_security_information_and_event_managerRange7.2.0
VendorProductVersionCPE
ibmqradar_security_information_and_event_manager*cpe:2.3:a:ibm:qradar_security_information_and_event_manager:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.006

Percentile

79.2%

Related for CVE-2014-0838