Lucene search

K
ibmIBMA575E3CCD8E9C9DFE30AF5502E5342C20C3969714E31C6CCD58276DFD2930BA8
HistoryMay 13, 2021 - 8:46 p.m.

Security Bulletin: User Behavior Analytics application add on to IBM QRadar SIEM is vulnerable to cross-site scripting (CVE-2021-20392)

2021-05-1320:46:49
www.ibm.com
10

0.001 Low

EPSS

Percentile

29.7%

Summary

User Behavior Analytics application add on to IBM QRadar SIEM is vulnerable to cross-site scripting.

Vulnerability Details

CVEID:CVE-2021-20392
**DESCRIPTION:**IBM QRadar User Behavior Analytics is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196000 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
QRadar User Behavior Analytics 1.0.0-4.0.1

Remediation/Fixes

Update to version 4.1.0 or later.

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

29.7%

Related for A575E3CCD8E9C9DFE30AF5502E5342C20C3969714E31C6CCD58276DFD2930BA8