IBM QRadar WinCollect Agent XML Injection Vulnerability

Vulnerability

A vulnerability exists in IBM QRadar WinCollect Agent versions 10.0.0 through 10.1.12, allowing remote attackers to inject XML data into parameter values. This issue arises from inadequate input validation of data that is presumed to be immutable, potentially leading to unauthorized modifications.

Impact

Exploitation of this vulnerability could allow for unauthorized XML data injection, potentially leading to further attacks such as XML External Entity (XXE) attacks or other injection-based exploits, depending on how the injected XML is processed.

Remediation

Users are advised to upgrade to IBM QRadar WinCollect Agent version 10.1.13. Instructions for upgrading can be found in the WinCollect 10.1.13 release notes.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
0.6
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.