Total vulnerabilities in the database
IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655.
Software | From | Fixed in |
---|---|---|
ibm / qradar_incident_forensics | 7.3.1-patch4 | 7.3.1-patch4.x |
ibm / qradar_incident_forensics | 7.3.1-patch3 | 7.3.1-patch3.x |
ibm / qradar_incident_forensics | 7.2.8-patch13 | 7.2.8-patch13.x |
ibm / qradar_incident_forensics | 7.2.8-patch8 | 7.2.8-patch8.x |
ibm / qradar_incident_forensics | 7.2.8-patch1 | 7.2.8-patch1.x |
ibm / qradar_incident_forensics | 7.2.0 | 7.2.8.x |
ibm / qradar_incident_forensics | 7.3.0 | 7.3.1.x |