VULNERABILITY INTELLIGENCE

CVE-2015-2011

CVSS score9 HIGH
EPSS probability2.21%
CISA KEVNot currently listed
Published2015-10-04
Last modified2026-06-17
CVSS vectorAV:N/AC:L/Au:S/C:C/I:C/A:C

Description

The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

Weakness classification

  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

Primary references