CyberRota Analysis
AI-GeneratedIBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 are vulnerable to an XML External Entity (XXE) injection due to improper handling of XML-formatted syslog events. This vulnerability allows unauthenticated attackers to exploit the event processing pipeline, potentially leading to data exposure or system compromise. Organizations using affected QRadar versions should prioritize remediation to mitigate the risk of exploitation.
Original NVD Description
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Related CVEs
Other vulnerabilities affecting the same vendor(s)