Vulnerability Details CVE-2016-2877
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.6%
CVSS Severity
CVSS v3 Score 3.3
CVSS v2 Score 2.1
Products affected by CVE-2016-2877
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6