IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811.
2019-01-29T16:29:00.437
2024-11-21T04:00:16.600
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | qradar_security_information_and_event_manager | ≤ 7.2.8 | Yes |
| Application | ibm | qradar_security_information_and_event_manager | ≤ 7.3.1 | Yes |
| Application | ibm | qradar_security_information_and_event_manager | 7.2.8 | Yes |
| Application | ibm | qradar_security_information_and_event_manager | 7.3.1 | Yes |