Lucene search

K
ibmIBM7323AA6061D98E3807E4A32D22FFA32DAB51AF98546CDAA765049215A41B802B
HistoryJun 29, 2023 - 3:06 p.m.

Security Bulletin: IBM QRadar SIEM is vulnerable to Hazardous Input Validation (CVE-2023-26273)

2023-06-2915:06:54
www.ibm.com
25
ibm qradar
siem
hazardous input validation
cve-2023-26273
security bulletin
vulnerability
authorization
update
fix

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

0.0005 Low

EPSS

Percentile

17.5%

Summary

IBM QRadar SIEM could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM QRadar SIEM has addressed the applicable vulnerability.

Vulnerability Details

CVEID:CVE-2023-26273
**DESCRIPTION:**IBM QRadar could allow an authenticated user to perform unauthorized actions due to hazardous input validation.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/248134 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM QRadar SIEM 7.5.0 - 7.5.0 UP5

Remediation/Fixes

IBM recommends customers update their systems promptly.

Product Version Remediation/First Fix
IBM QRadar SIEM 7.5.0 7.5.0 UP6

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_qradar_siemMatch7.5
CPENameOperatorVersion
ibm security qradar siemeq7.5

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

0.0005 Low

EPSS

Percentile

17.5%

Related for 7323AA6061D98E3807E4A32D22FFA32DAB51AF98546CDAA765049215A41B802B