Lucene search

K
ibmIBM41F5610251777690E4383C6E6EE8E9EA1CF5EB87FA3E338D09B470F3B5B3F337
HistoryJul 10, 2019 - 3:40 p.m.

Security Bulletin: IBM QRadar SIEM is vulnerable to Cross-Site Scripting (CVE-2018-2021)

2019-07-1015:40:02
www.ibm.com
5

0.001 Low

EPSS

Percentile

29.7%

Summary

IBM QRadar SIEM could allow users to embed code in the UI that may lead to Cross-Site Scripting.

Vulnerability Details

CVEID: CVE-2018-2021
**Description:**IBM QRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
**CVSS Base Score:**6.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/155345&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products and Versions

ยท IBM QRadar 7.3 to 7.3.2 GA

ยท IBM QRadar 7.2 to 7.2.8 Patch 15

Remediation/Fixes

IBM QRadar/QRM/QVM/QRIF/QNI 7.3.2 Patch 1

IBM QRadar/QRM/QVM/QRIF/QNI 7.3.1 Patch 8

IBM QRadar/QRM/QVM/QRIF/QNI 7.2.8 Patch 16

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

29.7%

Related for 41F5610251777690E4383C6E6EE8E9EA1CF5EB87FA3E338D09B470F3B5B3F337