CVE-2020-5013: XEE
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.
Other sources
IBM QRadar SIEM may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5013?
CVE-2020-5013 is a vulnerability in IBM QRadar SIEM that allows for a XML External Entity Injection (XXE) attack.
What is the severity of CVE-2020-5013?
The severity of CVE-2020-5013 is high, with a CVSS score of 8.1.
How does CVE-2020-5013 impact IBM QRadar SIEM?
CVE-2020-5013 may allow a remote attacker to expose sensitive information or consume memory resources.
Which versions of IBM QRadar SIEM are affected by CVE-2020-5013?
IBM QRadar SIEM versions from 7.3.0 to 7.3.3 and versions from 7.4.0 to 7.4.2 are affected by CVE-2020-5013.
How can I fix CVE-2020-5013 in IBM QRadar SIEM?
To fix CVE-2020-5013, upgrade to IBM QRadar SIEM version 7.3.3 Fix Pack 1 or later, or upgrade to IBM QRadar SIEM version 7.4.2 Fix Pack 1 or later.