First published: Thu Apr 29 2021(Updated: )
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.3.0<7.3.3 | |
IBM QRadar Security Information and Event Manager | >=7.4.0<7.4.2 | |
IBM QRadar Security Information and Event Manager | =7.3.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_2 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_4 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_5 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_6 | |
IBM QRadar Security Information and Event Manager | =7.3.3-fix_pack_7 | |
IBM QRadar Security Information and Event Manager | =7.4.2 | |
IBM QRadar Security Information and Event Manager | =7.4.2-fix_pack_1 | |
IBM QRadar Security Information and Event Manager | =7.4.2-fix_pack_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4979.
The severity of CVE-2020-4979 is critical.
IBM QRadar SIEM versions 7.3 and 7.4 are affected by CVE-2020-4979.
An attacker that is able to compromise or spoof traffic between hosts may be able to execute arbitrary commands.
Yes, there are fix packs available for IBM QRadar SIEM versions 7.3 and 7.4.