First published: Wed Jan 27 2021(Updated: )
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 190912.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.3.0 | |
IBM QRadar Security Information and Event Manager | =7.3.1 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p4 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p5 | |
IBM QRadar Security Information and Event Manager | =7.3.1-p6 | |
IBM QRadar Security Information and Event Manager | =7.3.2 | |
IBM QRadar Security Information and Event Manager | =7.3.2-interim_fix_01 | |
IBM QRadar Security Information and Event Manager | =7.3.2-interim_fix_02 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p1 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p2 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.2-p4 | |
IBM QRadar Security Information and Event Manager | =7.3.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p2 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p4 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p5 | |
IBM QRadar Security Information and Event Manager | =7.4.0 | |
IBM QRadar Security Information and Event Manager | =7.4.0-p1 | |
IBM QRadar Security Information and Event Manager | =7.4.0-p2 | |
IBM QRadar Security Information and Event Manager | =7.4.1 | |
IBM QRadar Security Information and Event Manager | =7.4.1-patch1 | |
IBM QRadar Security Information and Event Manager | =7.4.2 | |
IBM QRadar Security Information and Event Manager | =7.4.2-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4888 is critical with a CVSS score of 8.8.
A remote attacker can exploit the vulnerability by sending a malicious serialized Java object.
The vulnerability affects IBM QRadar SIEM versions 7.3.0 to 7.3.3 Patch 7 and 7.4.0 to 7.4.2 Patch 1.
The vulnerability is caused by insecure deserialization of user-supplied content by the Java deserialization function.
Yes, patches are available for IBM QRadar SIEM versions 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7.