VULNERABILITY INTELLIGENCE
CVE-2015-2011
CVSS score9 HIGH
EPSS probability2.21%
CISA KEVNot currently listed
Published2015-10-04
Last modified2026-06-17
CVSS vectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Description
The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
Weakness classification
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Primary references
- psirt@us.ibm.com — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory