CVE-2016-2868
low
CVSS v3
2.7
CVSS v2
4.0
VIR risk
2.7
Description
IBM Security QRadar SIEM 7.2.x before 7.2.7 allows remote authenticated administrators to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Predictions
Exploit likelihood
39%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21985774
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | qradar_security_information_and_event_manager | {"endIncluding":"7.2.6"} | |
References
Verify integrity in audit chain (admin only). AS-IS.