CVE Vulnerabilities

CVE-2016-2871

Published: Nov 30, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.

Affected Software

NameVendorStart VersionEnd Version
Qradar_security_information_and_event_managerIbm*7.1.0 (including)
Qradar_security_information_and_event_managerIbm7.2.0 (including)7.2.0 (including)
Qradar_security_information_and_event_managerIbm7.2.1 (including)7.2.1 (including)
Qradar_security_information_and_event_managerIbm7.2.2 (including)7.2.2 (including)
Qradar_security_information_and_event_managerIbm7.2.3 (including)7.2.3 (including)
Qradar_security_information_and_event_managerIbm7.2.4 (including)7.2.4 (including)
Qradar_security_information_and_event_managerIbm7.2.5 (including)7.2.5 (including)
Qradar_security_information_and_event_managerIbm7.2.6 (including)7.2.6 (including)

References