← Back

CVE-2014-6075

nvd nist
Published: Nov 28, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

Affected (17)

3 products
Qradar Risk Manager
Qradar Vulnerability Manager
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.1.0
Version 7.2.0
Version 7.2.1
Version 7.2.2
Version 7.2.3
Version 7.2.4
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.2.0
Version 7.2.1
Version 7.2.2
Version 7.2.3
Version 7.2.4
Configuration C
6 vulnerable

References (4)

Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.