Path traversal in IBM Qradar SIEM - CVE-2017-1723
Published: May 30, 2018
IBM Qradar SIEM
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to insufficient validation of user-supplied inout. A remote attacker can send a specially crafted URL request containing "dot dot" sequences (/../), conduct directory traversal attack and view arbitrary files on the system.