Page 33 of 165 results (0.016 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute arbitrary console commands by leveraging control of the server. El paquete de actualización automática anterior a 6.4 para IBM Security QRadar SIEM 7.2 MR1 y anteriores permite a atacantes remotos ejecutar comandos arbitrarios mediante el aprovechamiento de la consola de control del servidor. • http://osvdb.org/102553 http://www-01.ibm.com/support/docview.wss?uid=swg21663066 http://www.securityfocus.com/bid/65127 https://exchange.xforce.ibmcloud.com/vulnerabilities/90681 •

CVSS: 3.5EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in the Right Click Plugin context menus in IBM Security QRadar SIEM 7.1 and 7.2 before 7.2 MR1 Patch 1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en los menús de contexto Right Click Plugin de IBM Security QRadar SIEM 7.1 y 7.2 anterior a la versión 7.2 MR1 Patch 1 permite a usuarios remotos autenticados inyectar script web o HTML arbitrario a través de vectores sin especificar. • http://www-01.ibm.com/support/docview.wss?uid=swg21656875 http://www.securityfocus.com/bid/63938 https://exchange.xforce.ibmcloud.com/vulnerabilities/87912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 3.5EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en IBM Security QRadar SIEM 7.0 permite a usuarios remotos autenticados inyectar script web o HTML arbitrario a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21656875 http://www.securityfocus.com/bid/63939 https://exchange.xforce.ibmcloud.com/vulnerabilities/88556 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file. El agente WinCollect en IBM Security QRadar SIEM anterior a la versión 7.1.1.569824 permite a atacantes remotos evadir restricciones de acceso intencionadas mediante la inyección de (1) una DLL o (2) un archivo de confguración. • http://www-01.ibm.com/support/docview.wss?uid=swg21656875 https://exchange.xforce.ibmcloud.com/vulnerabilities/88361 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to execute operating-system commands via unknown vectors. ulnerabilidad no especificada en IBM QRadar Seguridad de la Información y Event Manager (SIEM) v7.x anterior a MR2 v7.1 Patch 1 permite a usuarios remotos autenticados ejecutar comandos del sistema operativo a través de vectores desconocidos. • http://www-01.ibm.com/support/docview.wss?uid=swg21639309 http://www.kb.cert.org/vuls/id/722868 https://exchange.xforce.ibmcloud.com/vulnerabilities/83872 •