CVE-2015-4957
MEDIUMIBM Qradar Security Information And Event Manager - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Scores
CVSS v3
5.4
EPSS
0.0017
EPSS Percentile
37.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
ibm/qradar_security_information_and_event_manager
Timeline
Published
Feb 15, 2016
Tracked Since
Feb 18, 2026