|
257071
|
4.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager qradar_incident_forensics
|
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trus…
|
CWE-352
Origin Validation Error
|
CVE-2016-9730
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257072
|
6.5 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM Reference #: 1999545.
|
CWE-287
Improper Authentication
|
CVE-2016-9729
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257073
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Referen…
|
CWE-89
SQL Injection
|
CVE-2016-9728
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257074
|
8.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager qradar_incident_forensics
|
IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute…
|
CWE-20
Improper Input Validation
|
CVE-2016-9727
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257075
|
8.8 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager qradar_incident_forensics
|
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulne…
|
CWE-20
Improper Input Validation
|
CVE-2016-9726
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257076
|
5.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate …
|
CWE-200
Information Exposure
|
CVE-2016-9725
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257077
|
8.1 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose high…
|
CWE-611
XXE
|
CVE-2016-9724
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257078
|
6.1 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager qradar_incident_forensics
|
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9723
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257079
|
5.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager qradar_incident_forensics
|
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.
|
CWE-200
Information Exposure
|
CVE-2016-9720
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257080
|
6.1 |
MEDIUM
Local
|
ibm
|
business_process_manager websphere
|
IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicio…
|
CWE-20
Improper Input Validation
|
CVE-2016-9693
|
2024-11-21 12:01 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|