IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
History

Tue, 18 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
Description IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Title IBM QRadar Advisor server-side request forgery
First Time appeared Ibm
Ibm qradar Advisor With Watson
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:qradar_advisor_with_watson:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_advisor_with_watson:2.6.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm qradar Advisor With Watson
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-03-18T14:19:44.773Z

Updated: 2025-03-18T14:29:41.607Z

Reserved: 2024-10-20T13:40:37.122Z

Link: CVE-2024-49822

cve-icon Vulnrichment

Updated: 2025-03-18T14:29:37.591Z

cve-icon NVD

Status : Received

Published: 2025-03-18T15:15:56.283

Modified: 2025-03-18T15:15:56.283

Link: CVE-2024-49822

cve-icon Redhat

No data.