CVE-2020-4512: OS Command Injection
Published Jul 14, 2020
·Updated
IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.
Affected Software
8 affected components
IBM QRadar Security Information and Event Manager>=7.3.0<=7.3.2
IBM QRadar Security Information and Event Manager=7.3.3
IBM QRadar Security Information and Event Manager=7.3.3-p1
IBM QRadar Security Information and Event Manager=7.3.3-p2
IBM QRadar Security Information and Event Manager=7.3.3-p3
IBM QRadar Security Information and Event Manager=7.4.0
IBM QRadar Security Information and Event Manager=7.4.0-p1
IBM QRadar Security Information and Event Manager=7.4.0-p2
Remediation
Patch Available
Event History
Jul 14, 2020
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4512.
2
What is the severity of CVE-2020-4512?
The severity of CVE-2020-4512 is critical.
3
Which versions of IBM QRadar SIEM are affected by CVE-2020-4512?
IBM QRadar SIEM versions 7.3 and 7.4 are affected by CVE-2020-4512.
4
How can a remote privileged user exploit CVE-2020-4512?
A remote privileged user can exploit CVE-2020-4512 to execute commands.
5
How can I fix CVE-2020-4512?
To fix CVE-2020-4512, apply the necessary security patches provided by IBM or upgrade to a non-vulnerable version of IBM QRadar SIEM.