CVE-2015-2011 describes a critical command injection vulnerability in the xmlrpc.cgi Webmin script within IBM QRadar SIEM versions 7.1 MR2 (before Patch 11 IF02) and 7.2.x (before 7.2.5 Patch 4). This flaw allows remote authenticated users to execute arbitrary commands with root privileges. The vulnerability carries a CVSS score of 9.0, indicating high severity due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Successful exploitation grants an attacker full control over the affected system. While there is no evidence of active exploitation (not in KEV or Hot List), and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has garnered some community discussion. The EPSS score is low, suggesting a low probability of exploitation in the wild despite its high theoretical impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1.0CPE matchmatch criteria | cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0:*:*:*:*:*:*:* | ||
7.2.0CPE matchmatch criteria | cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0:*:*:*:*:*:*:* | ||
7.2.1CPE matchmatch criteria | cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1:*:*:*:*:*:*:* | ||
7.2.2CPE matchmatch criteria | cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2:*:*:*:*:*:*:* | ||
7.2.3CPE matchmatch criteria | cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.