Cyber Security News

IBM QRadar SIEM XSS Flaw Let Attackers Execute JavaScript code

Two medium-severity vulnerabilities have been discovered in the widely used IBM QRadar SIEM, associated with Cross-Site Scripting (XSS) and Information disclosure. The vulnerabilities have been assigned with CVE-2023-40367 and CVE-2023-30994.

IBM has released patches for fixing these vulnerabilities and urges users to upgrade to the latest version of IBM QRadar.

CVE-2023-40367: IBM QRadar SIEM cross-site scripting

A threat actor can exploit this vulnerability, allowing them to insert arbitrary JavaScript code in the Web UI, which could alter the original functionality and potentially result in credentials disclosure within a trusted session.

The severity for this vulnerability has been given as 5.4 (Medium). This vulnerability falls under the weakness enumeration CWE-79 “Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting‘).”

Document
FREE Webinar

Why API Security Should be Your Top Priority

API security isn’t just a priority; it’s the lifeline of businesses and organizations. Yet, this interconnectivity brings with it an array of vulnerabilities that are often concealed beneath the surface.

CVE-2023-30994: IBM QRadar SIEM information disclosure

This vulnerability exists due to weaker cryptographic algorithms, which can be decrypted by a threat actor, potentially leading to the retrieval of highly sensitive information. The severity for this vulnerability has been given as 5.9 (Medium).

Affected Products

Products affected by these vulnerabilities are mentioned below

Affected ProductVersion(s)Fixed in Versions
IBM QRadar SIEM7.5.0 – 7.5.0 UP67.5.0 UP7

There is no evidence of these vulnerabilities being exploited by threat actors in the wild nor a publicly available exploit for exploiting this vulnerability.

However, several vulnerabilities were fixed as part of the security bulletin published by IBM for IBM QRadar SIEM. The severity of the vulnerabilities ranges from 3.7 (Low) to 9.8 (Critical).

Users of IBM QRadar SIEM are recommended to upgrade to the latest version of IBM QRadar to fix this vulnerability and prevent them from getting exploited by threat actors.

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago