Vulnerability Details CVE-2014-6075
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.6%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2014-6075
-
cpe:2.3:a:ibm:qradar_risk_manager:7.1.0
-
cpe:2.3:a:ibm:qradar_risk_manager:7.2.0
-
cpe:2.3:a:ibm:qradar_risk_manager:7.2.1
-
cpe:2.3:a:ibm:qradar_risk_manager:7.2.2
-
cpe:2.3:a:ibm:qradar_risk_manager:7.2.3
-
cpe:2.3:a:ibm:qradar_risk_manager:7.2.4
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4
-
cpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.0
-
cpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.1
-
cpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.2
-
cpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.3
-
cpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.4