IBM Security Bulletin: IBM QRadar SIEM is vulnerable to cross site scripting. (CVE-2017-1623)

The product allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality and allowing spoofing attacks.

CVE(s): CVE-2017-1623

Affected product(s) and affected version(s):

· IBM QRadar 7.3 to 7.3.0 Patch 7

· IBM QRadar 7.2 to 7.2.8 Patch 10

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2AAGT5L
X-Force Database: http://ift.tt/2CLExXK

The post IBM Security Bulletin: IBM QRadar SIEM is vulnerable to cross site scripting. (CVE-2017-1623) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2CvRaC7