IBM Security Bulletin: IBM QRadar SIEM is vulnerable to cross site scripting. (CVE-2017-1623)
The product allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality and allowing spoofing attacks.
CVE(s): CVE-2017-1623
Affected product(s) and affected version(s):
· IBM QRadar 7.3 to 7.3.0 Patch 7
· IBM QRadar 7.2 to 7.2.8 Patch 10
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2AAGT5L
X-Force Database: http://ift.tt/2CLExXK
The post IBM Security Bulletin: IBM QRadar SIEM is vulnerable to cross site scripting. (CVE-2017-1623) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2CvRaC7