First published: Thu Jul 15 2021(Updated: )
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | >=7.3.0<7.3.3 | |
IBM QRadar Security Information and Event Manager | >=7.4.0<7.4.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p1 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p2 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p3 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p4 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p5 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p6 | |
IBM QRadar Security Information and Event Manager | =7.3.3-p7 | |
IBM QRadar Security Information and Event Manager | =7.4.3 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM QRadar SIEM vulnerability is CVE-2020-4980.
The severity level of CVE-2020-4980 is medium with a severity value of 6.5.
IBM QRadar SIEM versions 7.3.0 to 7.3.3 and versions 7.4.0 to 7.4.3 are affected by CVE-2020-4980.
CVE-2020-4980 affects data protection in transit between hosts when encrypt host connections is not enabled, as well as data at rest.
You can find more information about CVE-2020-4980 in the IBM X-Force ID: 192539 and on the IBM support pages.