
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM QRadar SIEM 7.5 was identified with a stored cross-site scripting vulnerability (CVE-2023-50961). The vulnerability affects versions 7.5.x prior to 7.5.0 UP8, allowing users to embed arbitrary JavaScript code in the Web UI (IBM Security Bulletin).
The vulnerability has been assigned a CVSS Base score of 7.2 with a vector of (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). The vulnerability enables users to embed arbitrary JavaScript code in the Web UI, which can alter intended functionality and potentially lead to credentials disclosure within a trusted session (IBM Security Bulletin).
The exploitation of this vulnerability could result in credentials disclosure within trusted sessions and alteration of the intended Web UI functionality. The high CVSS score indicates significant potential impact on the confidentiality, integrity, and availability of the system (IBM Security Bulletin).
The vulnerability requires a remote authenticated attacker to execute, with network vector access and low attack complexity. The attack requires high privileges but no user interaction for successful exploitation (IBM Security Bulletin).
IBM has released version 7.5.0 UP8 to address this vulnerability. No workarounds are available, and IBM strongly encourages customers to update their systems promptly to the latest version (IBM Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."