Lucene search

K
vulnrichmentIbmVULNRICHMENT:CVE-2023-38020
HistoryFeb 02, 2024 - 3:36 a.m.

CVE-2023-38020 IBM SOAR QRadar Plugin App log injection

2024-02-0203:36:26
CWE-117
ibm
github.com
2
ibm
soar
qradar
plugin
log injection
vulnerability
x-force

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

6.2

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

CNA Affected

[
  {
    "vendor": "IBM",
    "product": "SOAR QRadar Plugin App",
    "versions": [
      {
        "status": "affected",
        "version": "1.0",
        "versionType": "semver",
        "lessThanOrEqual": "5.0.3"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

6.2

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-38020