CVE-2024-51462
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.37%
- CWE
- CWE-471
- Published
- 2025-01-17
- Last modified
- 2026-03-13
Affected products
- IBM QRadar WinCollect Agent
Weakness type
Related vulnerabilities
- CVE-2026-50481 — Azure Active Directory Elevation of Privilege Vulnerability
- CVE-2026-54267 — Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
- CVE-2026-44798 — Nautobot: GitRepository.current_head field should not be writable through REST API
- CVE-2026-8492 — Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035
- CVE-2025-33136 — IBM Aspera Faspex data modification
- CVE-2024-9876 — Application is vulnerable to Privilege escalation
- CVE-2024-55551 — An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject...
- CVE-2024-45672 — IBM Security Verify Bridge data manipulation