Multiple IBM QRadar Products CVE-2014-4829 Cross Site Request Forgery Vulnerability
BID:71346
Info
Multiple IBM QRadar Products CVE-2014-4829 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 71346 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-4829 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2014 12:00AM |
| Updated: | Nov 25 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM QRadar Vulnerability Manager 7.2.3 Patch 4 IBM QRadar Vulnerability Manager 7.2.3 IBM QRadar Vulnerability Manager 7.2 IBM QRadar Security Information and Event Manager 7.2.6 IBM QRadar Security Information and Event Manager 7.2.3 Patch 4 IBM QRadar Security Information and Event Manager 7.2.0 IBM QRadar Security Information and Event Manager 7.2 MR3 IBM QRadar Security Information and Event Manager 7.2 MR2 IBM QRadar Security Information and Event Manager 7.2 IBM QRadar Security Information and Event Manager 7.1MR2 Patch 1 IBM QRadar Security Information and Event Manager 7.1MR2 IBM QRadar Security Information and Event Manager 7.1MR1 IBM QRadar Security Information and Event Manager 7.1 MR2 Patch 9 IBM QRadar Security Information and Event Manager 7.1 MR2 Patch 8 IBM QRadar Security Information and Event Manager 7.1 MR2 IBM QRadar Security Information and Event Manager 7.1 IBM QRadar Security Information and Event Manager 7.0.1 IBM QRadar Security Information and Event Manager 7.0.0 IBM QRadar Security Information and Event Manager 7.0 MR5 IBM QRadar Security Information and Event Manager 7.0 IBM QRadar Risk Manager 7.2.3 Patch 4 IBM QRadar Risk Manager 7.2.3 IBM QRadar Risk Manager 7.2 MR2 IBM QRadar Risk Manager 7.1MR2 Patch 1 IBM QRadar Risk Manager 7.1MR2 IBM QRadar Risk Manager 7.1MR1 IBM QRadar Risk Manager 7.1 MR2 Patch 8 IBM QRadar Risk Manager 7.1 MR2 IBM QRadar Risk Manager 7.1 |
| Not Vulnerable: | |
Exploit / POC
Multiple IBM QRadar Products CVE-2014-4829 Cross Site Request Forgery Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Multiple IBM QRadar Products CVE-2014-4829 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple IBM QRadar Products CVE-2014-4829 Cross Site Request Forgery Vulnerability
References:
References: