Page 8 of 39 results (0.013 seconds)

CVSS: 3.5EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in the Right Click Plugin context menus in IBM Security QRadar SIEM 7.1 and 7.2 before 7.2 MR1 Patch 1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en los menús de contexto Right Click Plugin de IBM Security QRadar SIEM 7.1 y 7.2 anterior a la versión 7.2 MR1 Patch 1 permite a usuarios remotos autenticados inyectar script web o HTML arbitrario a través de vectores sin especificar. • http://www-01.ibm.com/support/docview.wss?uid=swg21656875 http://www.securityfocus.com/bid/63938 https://exchange.xforce.ibmcloud.com/vulnerabilities/87912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file. El agente WinCollect en IBM Security QRadar SIEM anterior a la versión 7.1.1.569824 permite a atacantes remotos evadir restricciones de acceso intencionadas mediante la inyección de (1) una DLL o (2) un archivo de confguración. • http://www-01.ibm.com/support/docview.wss?uid=swg21656875 https://exchange.xforce.ibmcloud.com/vulnerabilities/88361 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 3.5EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en IBM Security QRadar SIEM 7.0 permite a usuarios remotos autenticados inyectar script web o HTML arbitrario a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21656875 http://www.securityfocus.com/bid/63939 https://exchange.xforce.ibmcloud.com/vulnerabilities/88556 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to execute operating-system commands via unknown vectors. ulnerabilidad no especificada en IBM QRadar Seguridad de la Información y Event Manager (SIEM) v7.x anterior a MR2 v7.1 Patch 1 permite a usuarios remotos autenticados ejecutar comandos del sistema operativo a través de vectores desconocidos. • http://www-01.ibm.com/support/docview.wss?uid=swg21639309 http://www.kb.cert.org/vuls/id/722868 https://exchange.xforce.ibmcloud.com/vulnerabilities/83872 •