Lucene search

K
ibmIBMFA28B8BB3E590D6ECA0B5698CCC41756623A5AD300E940C8529E5E3D711BF1C5
HistoryJun 16, 2018 - 9:50 p.m.

Security Bulletin: IBM QRadar SIEM and QRadar Incident Forensics are vulnerable to cross-site request forgery (CVE-2016-9730)

2018-06-1621:50:45
www.ibm.com
9

EPSS

0.001

Percentile

29.8%

Summary

IBM QRadar SIEM and Incident Forensics allow web requests for sensitive operations to be stored in 3rd party websites which can lead to unauthorized alterations of the product and user data.

Vulnerability Details

CVEID: CVE-2016-9730**
DESCRIPTION:** IBM QRadar Incident Forensics is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/119759&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)

Affected Products and Versions

ā€¢ IBM QRadar SIEM 7.2.n
ā€¢ IBM QRadar Incident Forensics 7.2.n

Remediation/Fixes

ā€¢ IBM QRadar/QRM/QVM/QRIF 7.2.8 Patch 4

Workarounds and Mitigations

None

EPSS

0.001

Percentile

29.8%

Related for FA28B8BB3E590D6ECA0B5698CCC41756623A5AD300E940C8529E5E3D711BF1C5