CVE-2016-2877
Summary
| CVE | CVE-2016-2877 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-11-30 18:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file. |
Risk And Classification
Primary CVSS: v3.0 3.3 LOW from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.000450000 probability, percentile 0.137430000 (date 2026-05-10)
Problem Types: CWE-275 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 3.3 | LOW | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 2.0 | [email protected] | Primary | 2.1 | AV:L/AC:L/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Qradar Security Information And Event Manager | 7.2.0 | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.2.1 | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.2.2 | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.2.3 | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.2.4 | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.2.5 | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.2.6 | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | All | mr1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM QRadar SIEM CVE-2016-2877 Local Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Security Bulletin: IBM QRadar SIEM is vulnerable to incorrect permission assignment. (CVE-2016-2877) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.