CVE-2020-4993: Path Traversal
Published Apr 29, 2021
·Updated
IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.
Other sources
IBM QRadar SIEM when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks.
— IBM
Affected Software
13 affected components
IBM QRadar Security Information and Event Manager>=7.3.0<7.3.3
IBM QRadar Security Information and Event Manager>=7.4.0<7.4.2
IBM QRadar Security Information and Event Manager=7.3.3
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_1
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_2
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_3
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_4
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_5
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_6
IBM QRadar Security Information and Event Manager=7.3.3-fix_pack_7
IBM QRadar Security Information and Event Manager=7.4.2
IBM QRadar Security Information and Event Manager=7.4.2-fix_pack_1
IBM QRadar Security Information and Event Manager=7.4.2-fix_pack_2
Event History
Apr 29, 2021
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
May 5, 2021
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4993.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM QRadar SIEM when decompressing or verifying signature of zip files processes data in a way that …'
3
What is the severity of CVE-2020-4993?
The severity of CVE-2020-4993 is medium.
4
Which versions of IBM QRadar SIEM are affected by this vulnerability?
IBM QRadar SIEM versions 7.3 and 7.4 are affected by this vulnerability.
5
How can I fix CVE-2020-4993?
To fix CVE-2020-4993, update IBM QRadar SIEM to version 7.3.3 or 7.4.2 or later.