CVE-2020-4789: Path Traversal
IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 189302.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4789?
The severity of CVE-2020-4789 is medium with a severity value of 6.5.
How does CVE-2020-4789 affect IBM QRadar SIEM?
CVE-2020-4789 allows a remote attacker to traverse directories on the system and view arbitrary files on the system.
Which versions of IBM QRadar SIEM are affected by CVE-2020-4789?
IBM QRadar SIEM versions 7.3.0 to 7.3.3 Patch 5, 7.4.0 to 7.4.1 Patch 1, and 7.4.2 GA to 7.4.2 Patch 1 are affected by CVE-2020-4789.
How can I fix CVE-2020-4789 in IBM QRadar SIEM?
Upgrade to a patched version of IBM QRadar SIEM that addresses the vulnerability.
Where can I find more information about CVE-2020-4789?
You can find more information about CVE-2020-4789 on the IBM X-Force Exchange website and in the IBM support pages.