First published: Mon Aug 10 2020(Updated: )
IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. IBM X-Force ID: 181861.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.2.0<=7.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4486.
The severity of CVE-2020-4486 is high with a CVSS score of 8.1.
IBM QRadar versions 7.2.0 through 7.2.9 are affected by CVE-2020-4486.
CVE-2020-4486 allows an authenticated user to overwrite or delete arbitrary files in IBM QRadar after WinCollect installation.
Please refer to the IBM support page for guidance on how to mitigate or fix the vulnerability.