CVE-2017-1234
published 2017-06-27CVE-2017-1234: IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.73%
49.8th percentile
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123913.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | security_qradar_siem | — | — |
| ibm | security_qradar_siem | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks [fedora-all]
bugzilla·2018-01-29·CVSS 1.9
CVE-2017-7516 [LOW] CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks [fedora-all]
CVE-2017-7516 cpio: --no-absolute-filenames bypass via symlinks [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1539685,1539688
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after update
Bugzilla
CVE-2017-2888 SDL2: SDL: Integer overflow while creating a new RGB surface [epel-7]
bugzilla·2017-10-11·CVSS 8.8
CVE-2017-2888 [HIGH] CVE-2017-2888 SDL2: SDL: Integer overflow while creating a new RGB surface [epel-7]
CVE-2017-2888 SDL2: SDL: Integer overflow while creating a new RGB surface [epel-7]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1500623,1500735
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after
Bugzilla
CVE-2017-2885 mingw-libsoup: libsoup: Stack based buffer overflow with HTTP Chunked Encoding [fedora-all]
bugzilla·2017-08-10·CVSS 9.8
CVE-2017-2885 [CRITICAL] CVE-2017-2885 mingw-libsoup: libsoup: Stack based buffer overflow with HTTP Chunked Encoding [fedora-all]
CVE-2017-2885 mingw-libsoup: libsoup: Stack based buffer overflow with HTTP Chunked Encoding [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1479281
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users
Bugzilla
CVE-2017-2885 mingw-libsoup: libsoup: Stack based buffer overflow with HTTP Chunked Encoding [epel-7]
bugzilla·2017-08-10·CVSS 9.8
CVE-2017-2885 [CRITICAL] CVE-2017-2885 mingw-libsoup: libsoup: Stack based buffer overflow with HTTP Chunked Encoding [epel-7]
CVE-2017-2885 mingw-libsoup: libsoup: Stack based buffer overflow with HTTP Chunked Encoding [epel-7]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1479281
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users res
Bugzilla
CVE-2017-2885 libsoup: Stack based buffer overflow with HTTP Chunked Encoding [fedora-all]
bugzilla·2017-08-10·CVSS 9.8
CVE-2017-2885 [CRITICAL] CVE-2017-2885 libsoup: Stack based buffer overflow with HTTP Chunked Encoding [fedora-all]
CVE-2017-2885 libsoup: Stack based buffer overflow with HTTP Chunked Encoding [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1479281
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after
http://www.ibm.com/support/docview.wss?uid=swg22004948http://www.securityfocus.com/bid/99265https://exchange.xforce.ibmcloud.com/vulnerabilities/123913http://www.ibm.com/support/docview.wss?uid=swg22004948http://www.securityfocus.com/bid/99265https://exchange.xforce.ibmcloud.com/vulnerabilities/123913
2017-06-27
Published