VYPR
Unrated severityNVD Advisory· Published Oct 19, 2014· Updated May 6, 2026

CVE-2014-4833

CVE-2014-4833

Description

IBM QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allow remote authenticated users to gain elevated privileges via improper validation of input.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allow remote authenticated users to gain elevated privileges via improper validation of input.

Vulnerability

IBM QRadar SIEM QRM (QRadar Risk Manager) 7.1 MR1 and QRM/QVM (QRadar Vulnerability Manager) 7.2 MR2 contain an improper input validation vulnerability. A remote authenticated user can send specially crafted input to the affected components, bypassing intended access controls. The flaw affects QRM 7.1 MR1 and QRM/QVM 7.2 MR2 as identified in the official IBM security bulletin [1].

Exploitation

To exploit this vulnerability, an attacker must first obtain valid authentication credentials for the QRadar system. With authenticated access, the attacker can send invalid input that the application fails to validate properly. The exact sequence of steps is not publicly detailed, but the improper validation allows the attacker to escalate privileges. The attack requires network access to the affected service [1].

Impact

Successful exploitation allows a remote authenticated attacker to gain elevated privileges on the system. The CVSS v2 base score is 6.5 with a vector of AV:N/AC:L/Au:S/C:P/I:P/A:P, indicating partial compromise of confidentiality, integrity, and availability. The attacker can perform actions beyond their intended privilege level, potentially leading to full control of the affected component [1].

Mitigation

IBM released a security bulletin on October 16, 2014, addressing this vulnerability. The recommended mitigation is to apply the appropriate IBM QRadar, QRM, or QVM fix as provided in the bulletin [1]. The fix is available from IBM support. No workarounds are documented in the available references. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the last check.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0:*:*:*:*:*:*:*
  • IBM/QRadar SIEMllm-fuzzy
    Range: = 7.1 MR1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.