CVE-2019-4672

MEDIUM

IBM QRadar Advisor <2.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 171438.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/3379965
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/171438

Scores

CVSS v3 5.3
EPSS 0.0143
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
ibm/qradar_advisor 1.1 - 2.5.1
Published Feb 25, 2020
Tracked Since Feb 18, 2026