Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
| Software | From | Fixed in |
|---|---|---|
| ibm / qradar_security_information_and_event_manager | 7.2.0 | 7.2.0.x |
| ibm / security_qradar_incident_forensics | 7.2.5 | 7.2.5.x |
| ibm / qradar_security_information_and_event_manager | 7.2.4 | 7.2.4.x |
| ibm / security_qradar_incident_forensics | 7.2.3 | 7.2.3.x |
| ibm / security_qradar_incident_forensics | 7.2.0 | 7.2.0.x |
| ibm / qradar_security_information_and_event_manager | 7.2.6 | 7.2.6.x |
| ibm / qradar_security_information_and_event_manager | 7.2.1 | 7.2.1.x |
| ibm / security_qradar_incident_forensics | 7.2.1 | 7.2.1.x |
| ibm / security_qradar_incident_forensics | 7.2.2 | 7.2.2.x |
| ibm / security_qradar_incident_forensics | 7.2.6 | 7.2.6.x |
| ibm / qradar_security_information_and_event_manager | 7.2.5 | 7.2.5.x |
| ibm / qradar_security_information_and_event_manager | 7.2.2 | 7.2.2.x |
| ibm / qradar_security_information_and_event_manager | 7.2.3 | 7.2.3.x |
| ibm / security_qradar_incident_forensics | 7.2.4 | 7.2.4.x |