Multiple IBM QRadar Products CVE-2014-4828 Clickjacking Vulnerability
BID:71076
Info
Multiple IBM QRadar Products CVE-2014-4828 Clickjacking Vulnerability
| Bugtraq ID: | 71076 |
| Class: | Design Error |
| CVE: |
CVE-2014-4828 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2014 12:00AM |
| Updated: | Oct 08 2014 12:00AM |
| Credit: | IBM Security Systems Ethical Hacking Team |
| Vulnerable: |
Juniper Security Threat Response Manager 2013.2 Juniper Security Threat Response Manager 2012.1 Juniper Secure Analytics 2014.2R3 Juniper Secure Analytics 2014.2R2 Juniper Secure Analytics 2014.2 Juniper Secure Analytics 2014.1 Juniper Secure Analytics 2013.2R8 Juniper Secure Analytics 2013.2 IBM QRadar Vulnerability Manager 7.2 MR2 IBM QRadar Security Information and Event Manager 7.2.6 IBM QRadar Security Information and Event Manager 7.2.0 IBM QRadar Risk Manager 7.2 MR2 IBM QRadar Risk Manager 7.1MR1 |
| Not Vulnerable: |
Juniper Security Threat Response Manager 2013.2R9 Juniper Secure Analytics 2014.3R1 Juniper Secure Analytics 2013.2R9 |
Discussion
Multiple IBM QRadar Products CVE-2014-4828 Clickjacking Vulnerability
Multiple IBM QRadar products are prone to a clickjacking vulnerability.
Successful exploits will allow an authenticated attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
The following product versions are affected:
IBM QRadar Vulnerability Manager 7.2 MR2
IBM QRadar Risk Manager 7.2 MR2, and 7.1 MR1
IBM QRadar Security Information and Event Manager 7.1, 7.2, 7.2 MR2, and 7.1 MR1
Multiple IBM QRadar products are prone to a clickjacking vulnerability.
Successful exploits will allow an authenticated attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
The following product versions are affected:
IBM QRadar Vulnerability Manager 7.2 MR2
IBM QRadar Risk Manager 7.2 MR2, and 7.1 MR1
IBM QRadar Security Information and Event Manager 7.1, 7.2, 7.2 MR2, and 7.1 MR1
Exploit / POC
Multiple IBM QRadar Products CVE-2014-4828 Clickjacking Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted webpage.
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted webpage.
References
Multiple IBM QRadar Products CVE-2014-4828 Clickjacking Vulnerability
References:
References: