Vulnerability Details CVE-2016-2881
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended access restrictions via modified request parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.4
Products affected by CVE-2016-2881
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5
-
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6