CVE-2019-4262

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ibmCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/PR:N/I:L/AC:L/S:U/C:N/A:N/UI:N/RC:C/RL:O/E:U
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.2.0 ≤
𝑥
< 7.2.8
ibmqradar_security_information_and_event_manager
7.3.0 ≤
𝑥
< 7.3.2
ibmqradar_security_information_and_event_manager
7.2.8
ibmqradar_security_information_and_event_manager
7.2.8:p1
ibmqradar_security_information_and_event_manager
7.2.8:p10
ibmqradar_security_information_and_event_manager
7.2.8:p11
ibmqradar_security_information_and_event_manager
7.2.8:p12
ibmqradar_security_information_and_event_manager
7.2.8:p13
ibmqradar_security_information_and_event_manager
7.2.8:p14
ibmqradar_security_information_and_event_manager
7.2.8:p15
ibmqradar_security_information_and_event_manager
7.2.8:p16
ibmqradar_security_information_and_event_manager
7.2.8:p2
ibmqradar_security_information_and_event_manager
7.2.8:p3
ibmqradar_security_information_and_event_manager
7.2.8:p4
ibmqradar_security_information_and_event_manager
7.2.8:p5
ibmqradar_security_information_and_event_manager
7.2.8:p6
ibmqradar_security_information_and_event_manager
7.2.8:p7
ibmqradar_security_information_and_event_manager
7.2.8:p8
ibmqradar_security_information_and_event_manager
7.2.8:p9
ibmqradar_security_information_and_event_manager
7.3.2
ibmqradar_security_information_and_event_manager
7.3.2:p1
ibmqradar_security_information_and_event_manager
7.3.2:p2
ibmqradar_security_information_and_event_manager
7.3.2:p3
𝑥
= Vulnerable software versions