Boletines de Vulnerabilidades

IBM Security Bulletin: IBM QRadar SIEM is vulnerable to untrusted XML External Entity uploads. (CVE-2016-2868)

   
Software afectado IBM
 
XML External Entity injection in the UI of QRadar allows someone with privileges to upload unvalidated XML.CVE(s): CVE-2016-2868Affected product(s) and affected version(s):IBM QRadar SIEM 7.2.nRefer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21985774X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/112765

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-qradar-siem-is-vulnerable-to-untrusted-xml-external-entity-uploads-cve-2016-2868/