Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force ID: 103921.
2018-03-29T18:29:00.997
2024-11-21T02:26:35.310
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | qradar_security_information_and_event_manager | < 7.2.5 | Yes |
Application | ibm | qradar_security_information_and_event_manager | 7.1.0 | Yes |
Application | ibm | qradar_security_information_and_event_manager | 7.1.0 | Yes |
Application | ibm | qradar_security_information_and_event_manager | 7.1.0 | Yes |
Application | ibm | qradar_security_information_and_event_manager | 7.2.5 | Yes |
Application | ibm | qradar_security_information_and_event_manager | 7.2.5 | Yes |
Application | ibm | qradar_security_information_and_event_manager | 7.2.5 | Yes |