First published: Wed Jun 16 2021(Updated: )
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
<2.1.0 | ||
Apache Log4j | >=1.2<2.0 | |
<1.2.18.1 | ||
IBM QRadar SIEM | <=7.5 - 7.5.0 UP7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9493 is a deserialization flaw found in Apache Chainsaw versions prior to 2.1.0.
CVE-2020-9493 allows a remote attacker to execute arbitrary code on the system through an unsafe deserialization flaw when reading log events.
Apache Chainsaw versions prior to 2.1.0, Apache Log4j versions between 1.2 and 2.0 (inclusive), Qos Reload4j versions prior to 1.2.18.1, and IBM QRadar SIEM versions up to 7.5.0 UP7 are affected by CVE-2020-9493.
CVE-2020-9493 has a severity rating of 9.8 (Critical).
To mitigate CVE-2020-9493, update Apache Chainsaw to version 2.1.0 or later, update Apache Log4j to a version higher than 2.0, update Qos Reload4j to version 1.2.18.1 or later, and update IBM QRadar SIEM to a version higher than 7.5.0 UP7.