Lucene search

K
nvd[email protected]NVD:CVE-2019-4262
HistorySep 26, 2019 - 3:15 p.m.

CVE-2019-4262

2019-09-2615:15:10
CWE-918
web.nvd.nist.gov
2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.9%

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.

Affected configurations

NVD
Node
ibmqradar_security_information_and_event_managerRange7.2.07.2.8
OR
ibmqradar_security_information_and_event_managerRange7.3.07.3.2
OR
ibmqradar_security_information_and_event_managerMatch7.2.8-
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p1
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p10
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p11
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p12
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p13
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p14
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p15
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p16
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p2
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p3
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p4
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p5
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p6
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p7
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p8
OR
ibmqradar_security_information_and_event_managerMatch7.2.8p9
OR
ibmqradar_security_information_and_event_managerMatch7.3.2-
OR
ibmqradar_security_information_and_event_managerMatch7.3.2p1
OR
ibmqradar_security_information_and_event_managerMatch7.3.2p2
OR
ibmqradar_security_information_and_event_managerMatch7.3.2p3

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.9%

Related for NVD:CVE-2019-4262