VDB
CVE-2017-1133
CVE-2017-1133
PUBLISHED
CVSS 3.5 LOW
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
EPSS 0.26% · 49.5th percentile
Risk Scores
CVSS 2.0
3.5
EPSS Score
0.26%
49.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ibm | qradar_incident_forensics | 7.2.5, 7.2.6, 7.2.8 |
| IBM Corporation | QRadar SIEM | 7.2, 7.1 MR1, 7.1 |
| ibm | qradar_security_information_and_event_manager | 7.2.0, 7.2.2, 7.2.4 |
Timeline
- Mar 7, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score