Modification of Assumed-Immutable Data (MAID)
CVE-2024-51462
Summary
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
- LOW
- LOCAL
- LOW
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-471 - Modification of Assumed-Immutable Data (MAID)
The software does not properly protect an assumed-immutable element from being modified by an attacker.
References
Advisory Timeline
- Published