IBM QRadar Risk Manager 7.2.0

CPE Details

IBM QRadar Risk Manager 7.2.0
7.2.0
2014-11-28
15h30 +00:00
2015-02-18
17h53 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ibm:qradar_risk_manager:7.2.0:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

qradar_risk_manager

Version

7.2.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2017-1724 2018-04-26 14h00 +00:00 IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.
6.1
Moyen
CVE-2014-4829 2014-11-28 01h00 +00:00 Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
6.8
CVE-2014-4831 2014-11-28 01h00 +00:00 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.
5.8
CVE-2014-4832 2014-11-28 01h00 +00:00 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
4.3
CVE-2014-6075 2014-11-28 01h00 +00:00 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
5