IBM QRadar Risk Manager 7.2.3

CPE Details

IBM QRadar Risk Manager 7.2.3
7.2.3
2014-11-28
15h30 +00:00
2015-02-18
17h53 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:qradar_risk_manager:7.2.3:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

qradar_risk_manager

Version

7.2.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-1724 2018-04-26 14h00 +00:00 IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.
6.1
Medium
CVE-2014-4829 2014-11-28 01h00 +00:00 Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
6.8
CVE-2014-4831 2014-11-28 01h00 +00:00 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.
5.8
CVE-2014-4832 2014-11-28 01h00 +00:00 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
4.3
CVE-2014-6075 2014-11-28 01h00 +00:00 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
5