CVE-2020-4979: Critical severity IBM QRadar Security Information and Event Manager vulnerability
Published Apr 29, 2021
·Updated
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.
Other sources
IBM QRadar SIEM is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands.
— IBM
Affected Software
13 affected components
IBM QRadar Security Information and Event Manager>=7.3.0<7.3.3
IBM QRadar Security Information and Event Manager>=7.4.0<7.4.2
IBM QRadar Security Information and Event Manager=7.3.3
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_1
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_2
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_3
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_4
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_5
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_6
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_7
IBM QRadar Security Information and Event Manager=7.4.2
IBM QRadar Security Information and Event Manager=7.4.2-fix_pack_1
IBM QRadar Security Information and Event Manager=7.4.2-fix_pack_2
Event History
Apr 29, 2021
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
May 5, 2021
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4979.
2
What is the severity of CVE-2020-4979?
The severity of CVE-2020-4979 is critical.
3
Which version of IBM QRadar SIEM is affected by CVE-2020-4979?
IBM QRadar SIEM versions 7.3 and 7.4 are affected by CVE-2020-4979.
4
How can an attacker exploit CVE-2020-4979?
An attacker that is able to compromise or spoof traffic between hosts may be able to execute arbitrary commands.
5
Is there a fix available for CVE-2020-4979?
Yes, there are fix packs available for IBM QRadar SIEM versions 7.3 and 7.4.