VulnerabilityModified
CVE-2019-4672
IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system.
MEDIUM 5.3EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 171438.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.43% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- ibm/qradar advisor
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/171438VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/3379965Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/171438VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/3379965Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.