Lucene search

K
ibmIBMF5898D703C8DB7EDAFE912FBEDAAB47D7799B8A146C8FF801110D00172D3B143
HistoryJun 16, 2018 - 9:44 p.m.

Security Bulletin: IBM QRadar SIEM is vulnerable to SQL Injection. (CVE-2016-2873)

2018-06-1621:44:55
www.ibm.com
6

EPSS

0.001

Percentile

42.5%

Summary

IBM QRadar SIEM was found to be vulnerable to SQL injection.

Vulnerability Details

CVE-ID: CVE-2016-2873 **Description:**IBM QRadar is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. **CVSS Base Score:**7.6 **CVSS Temporal Score:**See https://exchange.xforce.ibmcloud.com/vulnerabilities/112835 for the current score **CVSS Environmental Score:***Undefined CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Affected Products and Versions

ยท IBM QRadar SIEM 7.2.n

ยท IBM QRadar SIEM 7.1.n

Remediation/Fixes

ยท QRadar / QRM / QVM / QRIF 7.2.7

ยท IBM QRadar SIEM 7.1 MR2 Patch 13

Workarounds and Mitigations

None

EPSS

0.001

Percentile

42.5%

Related for F5898D703C8DB7EDAFE912FBEDAAB47D7799B8A146C8FF801110D00172D3B143