CVE-2016-9740Injection in Corporation Qradar Siem

Severity
7.5HIGHNVD
EPSS
0.9%
top 24.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 17

Description

IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7j3m-w8mw-wq27: IBM QRadar 72022-05-17
CVEList
CVE-2016-9740: IBM QRadar 72017-03-07

📋Vendor Advisories

2
Microsoft
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter as demonstrated by the first2019-10-08
Red Hat
python: CRLF injection via the host part of the url passed to urlopen()2019-07-04
CVE-2016-9740 — Injection in Corporation Qradar Siem | cvebase