CVE-2020-4280: Critical severity ibm qradar security information and event manager vulnerability
IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 176140.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4280?
CVE-2020-4280 is a vulnerability in IBM QRadar SIEM 7.3 and 7.4 that could allow a remote attacker to execute arbitrary commands on the system.
How does CVE-2020-4280 occur?
CVE-2020-4280 occurs due to insecure deserialization of user-supplied content by the Java deserialization function in IBM QRadar SIEM 7.3 and 7.4.
What is the severity of CVE-2020-4280?
CVE-2020-4280 is rated as critical with a severity score of 8.8.
Which versions of IBM QRadar SIEM are affected by CVE-2020-4280?
CVE-2020-4280 affects IBM QRadar SIEM 7.3.0 to 7.3.3-p4 and 7.4.0 to 7.4.1.
How can CVE-2020-4280 be exploited?
CVE-2020-4280 can be exploited by sending a malicious serialized Java object.