CVE-2014-0838

IBM Security QRadar SIEM <7.2 MR1 - RCE

Title source: llm
STIX 2.1

Description

The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute arbitrary console commands by leveraging control of the server.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/102553
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65127
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90681
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21663066

Scores

EPSS 0.0153
EPSS Percentile 72.1%

Details

Status published
Products (1)
ibm/qradar_security_information_and_event_manager < 7.2.0
Published Jan 30, 2014
Tracked Since Feb 18, 2026