Vulnerability Name: | CVE-2016-2877 (CCN-112850) | ||||||||||||
Assigned: | 2016-07-26 | ||||||||||||
Published: | 2016-07-26 | ||||||||||||
Updated: | 2016-12-23 | ||||||||||||
Summary: | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file. | ||||||||||||
CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-275 | ||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-2877 Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21987773 Source: CCN Type: IBM Security Bulletin 1987773 (Security QRadar SIEM) IBM QRadar SIEM is vulnerable to incorrect permission assignment. (CVE-2016-2877) Source: BID Type: UNKNOWN 95002 Source: CCN Type: BID-95002 IBM QRadar SIEM CVE-2016-2877 Local Security Bypass Vulnerability Source: XF Type: UNKNOWN ibm-qradar-cve20162877-write-files(112850) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |