CVE-2020-4929: XSS
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191706.
Other sources
IBM QRadar SIEM is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4929.
What is the title of this vulnerability?
The title of this vulnerability is 'IBM QRadar SIEM is vulnerable to cross-site scripting.'
What is the severity of CVE-2020-4929?
The severity of CVE-2020-4929 is medium with a severity value of 5.4.
Which versions of IBM QRadar SIEM are affected?
IBM QRadar SIEM versions 7.3 and 7.4 are affected.
How can this vulnerability be fixed?
To fix this vulnerability, upgrade to a version of IBM QRadar SIEM that is not affected or apply the relevant fix pack.