CVE Vulnerabilities

CVE-2016-2877

Published: Nov 30, 2016 | Modified: Apr 12, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.

Affected Software

NameVendorStart VersionEnd Version
Qradar_security_information_and_event_managerIbm*7.1.0 (including)
Qradar_security_information_and_event_managerIbm7.2.0 (including)7.2.0 (including)
Qradar_security_information_and_event_managerIbm7.2.1 (including)7.2.1 (including)
Qradar_security_information_and_event_managerIbm7.2.2 (including)7.2.2 (including)
Qradar_security_information_and_event_managerIbm7.2.3 (including)7.2.3 (including)
Qradar_security_information_and_event_managerIbm7.2.4 (including)7.2.4 (including)
Qradar_security_information_and_event_managerIbm7.2.5 (including)7.2.5 (including)
Qradar_security_information_and_event_managerIbm7.2.6 (including)7.2.6 (including)

References