Lucene search

K
ibmIBMA630662FE34DE4FFE78B66F63807A4B014627C4DC12F3949118914F689EA2124
HistoryJun 16, 2018 - 9:25 p.m.

Security Bulletin: IBM QRadar Incident Forensics 7.2.4 is vulnerable to a cross site scripting vulnerability. (CVE-2015-1919)

2018-06-1621:25:06
www.ibm.com
6

EPSS

0.001

Percentile

47.3%

Summary

A cross site scripting vulnerability was found to affect IBM QRadar Incident Forensics.

Vulnerability Details

CVEID:CVE-2015-1919

DESCRIPTION:
IBM QRadar Incident Forensics is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL. If clicked, the URL could execute script in a victim’s Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/102085 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

Β· IBM QRadar Incident Forensics 7.2.4 and prior.

Remediation/Fixes

Β· IBM QRdar Incident Forensics 7.2.5

Workarounds and Mitigations

None

EPSS

0.001

Percentile

47.3%

Related for A630662FE34DE4FFE78B66F63807A4B014627C4DC12F3949118914F689EA2124