CVE-2021-20392Cross-site Scripting in IBM Qradar User Behavior Analytics

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 67.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 24

Description

IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5ibm/qradar_siem1.0.0, 4.1.1+1

🔴Vulnerability Details

2
GHSA
GHSA-fvm4-pf5q-h76x: IBM QRadar User Behavior Analytics 12022-05-24
CVEList
CVE-2021-20392: IBM QRadar User Behavior Analytics 12021-05-14

💬Community

1
Bugzilla
CVE-2019-20392 libyang: invalid memory access when if-feature statement is used inside a list key node2020-01-22
CVE-2021-20392 — Cross-site Scripting in IBM | cvebase