Vulnerability Name: | CVE-2014-0835 (CCN-90678) | ||||||||
Assigned: | 2014-01-24 | ||||||||
Published: | 2014-01-24 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify console Auto Update settings. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0835 Source: CCN Type: JSA10614 Security Threat Response Manager: Multiple vulnerabilities Source: OSVDB Type: UNKNOWN 102554 Source: FULLDISC Type: UNKNOWN 20140124 ADV: IBM QRadar SIEM Source: CCN Type: SA56653 IBM QRadar SIEM Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 56653 Source: CCN Type: SA56949 Juniper Security Threat Response Manager Multiple Vulnerabilities Source: CCN Type: Thomas Pollet IBM QRadar SIEM CSRF - XSS - MITM - RCE Source: MISC Type: UNKNOWN http://thomaspollet.blogspot.be/2014/01/ibm-qradar-siem-csrf-xss-mitm-rce.html Source: CCN Type: IBM Security Bulletin 1663066 Multiple vulnerabilities in IBM QRadar SIEM (CVE-2014-0838, CVE-2014-0835, CVE-2014-0836, CVE-2014-0837) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21663066 Source: BID Type: UNKNOWN 65127 Source: CCN Type: BID-65127 IBM QRadar Security Information and Event Manager Multiple Security Vulnerabilities Source: XF Type: UNKNOWN ibm-qradar-cve20140835-csrf(90678) Source: XF Type: UNKNOWN ibm-qradar-cve20140835-csrf(90678) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |