← All CVEs

CVE-2016-9722

medium · 4.2

IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.

4.2
CVSS
12.0%
EPSS (exploit prob.)
96th
EPSS percentile
2018-01-10
Published

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Weaknesses

CWE-284

Affected products

VendorProductAffected versions
ibmqradar_security_information_and_event_manager7.2.0
ibmqradar_security_information_and_event_manager7.2.1
ibmqradar_security_information_and_event_manager7.2.2
ibmqradar_security_information_and_event_manager7.2.3
ibmqradar_security_information_and_event_manager7.2.4
ibmqradar_security_information_and_event_manager7.2.5
ibmqradar_security_information_and_event_manager7.2.6
ibmqradar_security_information_and_event_manager7.2.7
ibmqradar_security_information_and_event_manager7.2.8
ibmqradar_security_information_and_event_manager7.3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-9722