CVE-2020-4485: Medium severity ibm qradar security information and event manager vulnerability
IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security mechanisms in future attacks. IBM X-Force ID: 181860.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4485?
CVE-2020-4485 is a vulnerability in IBM QRadar 7.2.0 through 7.2.9 that allows an authenticated user to disable the Wincollect service.
How does CVE-2020-4485 affect IBM QRadar?
CVE-2020-4485 affects IBM QRadar 7.2.0 through 7.2.9 by allowing an authenticated user to disable the Wincollect service.
What is the severity of CVE-2020-4485?
The severity of CVE-2020-4485 is medium with a CVSS score of 6.5.
How can an attacker exploit CVE-2020-4485?
An attacker can exploit CVE-2020-4485 by using the vulnerability to disable the Wincollect service, which could aid in bypassing security mechanisms for future attacks.
Is there a fix available for CVE-2020-4485?
Yes, IBM has released a fix for CVE-2020-4485. Please refer to the IBM support page for more information.