Vulnerability Bulletins

IBM SECURITY BULLETIN: Webmin as used in IBM QRadar SIEM is vulnerable to Execute code as root. (CVE-2015-2011)

   
Affected software IBM
 
The xmlrpc.cgi Webmin script allows arbitrary command execution and escalation of privileges. CVE(s): CVE-2015-2011 Affected product(s) and affected version(s): · IBM QRadar SIEM 7.2.x. · IBM QRadar SIEM 7.1 MR2 Patch 1 to Patch 10. Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21965817 X-Force Database:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_webmin_as_used_in_ibm_qradar_siem_is_vulnerable_to_execute_code_as_root_cve_2015_2011?lang=en_us