First published: Wed Jan 27 2021(Updated: )
IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 189302.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.3.0 | |
IBM QRadar Security Information and Event Manager | =7.3.1 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p4 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p5 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p6 | |
IBM QRadar Security Information and Event Manager | =7.3.2 | |
IBM QRadar Security Information and Event Manager | =7.3.2-interim_fix_01 | |
IBM QRadar Security Information and Event Manager | =7.3.2-interim_fix_02 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p1 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p2 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p4 | |
IBM QRadar Security Information and Event Manager | =7.3.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p2 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p4 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p5 | |
IBM QRadar Security Information and Event Manager | =7.4.0 | |
IBM QRadar Security Information and Event Manager | =7.4.0-p1 | |
IBM QRadar Security Information and Event Manager | =7.4.0-p2 | |
IBM QRadar Security Information and Event Manager | =7.4.1 | |
IBM QRadar Security Information and Event Manager | =7.4.1-patch1 | |
IBM QRadar Security Information and Event Manager | =7.4.2 | |
IBM QRadar Security Information and Event Manager | =7.4.2-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4789 is medium with a severity value of 6.5.
CVE-2020-4789 allows a remote attacker to traverse directories on the system and view arbitrary files on the system.
IBM QRadar SIEM versions 7.3.0 to 7.3.3 Patch 5, 7.4.0 to 7.4.1 Patch 1, and 7.4.2 GA to 7.4.2 Patch 1 are affected by CVE-2020-4789.
Upgrade to a patched version of IBM QRadar SIEM that addresses the vulnerability.
You can find more information about CVE-2020-4789 on the IBM X-Force Exchange website and in the IBM support pages.