Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Qradar Security Information And Event Manager | 7.1.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21987776Vendor Advisory
- http://www.securityfocus.com/bid/95004
- http://www-01.ibm.com/support/docview.wss?uid=swg21987776Vendor Advisory
- http://www.securityfocus.com/bid/95004
FAQ
What is CVE-2016-2878?
CVE-2016-2878 is a vulnerability with a CVSS score of 8.0 (HIGH). Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to hijack the authentication of arbitrary users for re...
How severe is CVE-2016-2878?
CVE-2016-2878 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2878?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Qradar Security Information And Event Manager.