First published: Tue May 04 2021(Updated: )
IBM QRadar contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.3.0<7.3.3 | |
IBM QRadar Security Information and Event Manager | >=7.4.0<7.4.2 | |
IBM QRadar Security Information and Event Manager | =7.3.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_2 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_4 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_5 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_6 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_7 | |
IBM QRadar Security Information and Event Manager | =7.4.2 | |
IBM QRadar Security Information and Event Manager | =7.4.2-fix_pack_1 | |
IBM QRadar Security Information and Event Manager | =7.4.2-fix_pack_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID associated with this issue is CVE-2020-4932.
The severity of CVE-2020-4932 is high.
The affected software is IBM QRadar Security Information and Event Manager versions 7.3.0 to 7.3.3 and versions 7.4.0 to 7.4.2.
The CWE associated with this vulnerability is CWE-798.
To fix CVE-2020-4932, you should upgrade IBM QRadar Security Information and Event Manager to version 7.3.3 or higher for versions 7.3.x and version 7.4.2 or higher for versions 7.4.x.