IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qradar_risk_manager | Ibm | 7.1.0 (including) | 7.1.0 (including) |
Qradar_risk_manager | Ibm | 7.2.0 (including) | 7.2.0 (including) |
Qradar_risk_manager | Ibm | 7.2.1 (including) | 7.2.1 (including) |
Qradar_risk_manager | Ibm | 7.2.2 (including) | 7.2.2 (including) |
Qradar_risk_manager | Ibm | 7.2.3 (including) | 7.2.3 (including) |
Qradar_risk_manager | Ibm | 7.2.4 (including) | 7.2.4 (including) |