CVE-2015-2005

EUVD-2015-2118
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.1.0
ibmqradar_security_information_and_event_manager
7.2.0
ibmqradar_security_information_and_event_manager
7.2.1
ibmqradar_security_information_and_event_manager
7.2.2
ibmqradar_security_information_and_event_manager
7.2.3
ibmqradar_security_information_and_event_manager
7.2.4
𝑥
= Vulnerable software versions