Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2016-9722

Severity
4.2MEDIUM
EPSS
32.0%
top 3.19%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 10
Latest updateMay 14

Description

IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-p7h8-p48v-gf6r: IBM QRadar 72022-05-14
CVEList
CVE-2016-9722: IBM QRadar 72018-01-10

💥Exploits & PoCs

1
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)2018-07-11
CVE-2016-9722 (MEDIUM CVSS 4.2) | IBM QRadar 7.2 and 7.3 specifies pe | cvebase.io