CVE-2020-4932: High severity ibm qradar security information and event manager vulnerability
IBM QRadar contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Other sources
IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 191748.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID associated with this issue?
The vulnerability ID associated with this issue is CVE-2020-4932.
What is the severity of CVE-2020-4932?
The severity of CVE-2020-4932 is high.
What is the affected software?
The affected software is IBM QRadar Security Information and Event Manager versions 7.3.0 to 7.3.3 and versions 7.4.0 to 7.4.2.
What is the CWE associated with this vulnerability?
The CWE associated with this vulnerability is CWE-798.
How can I fix CVE-2020-4932?
To fix CVE-2020-4932, you should upgrade IBM QRadar Security Information and Event Manager to version 7.3.3 or higher for versions 7.3.x and version 7.4.2 or higher for versions 7.4.x.