CVE-2021-20337: High severity ibm qradar security information and event manager vulnerability
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448.
Other sources
IBM QRadar uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is vulnerability ID CVE-2021-20337?
CVE-2021-20337 is a vulnerability in IBM QRadar SIEM that uses weaker than expected cryptographic algorithms, allowing an attacker to decrypt sensitive information.
What is the severity of vulnerability CVE-2021-20337?
The severity of vulnerability CVE-2021-20337 is high with a CVSS score of 7.5.
Which versions of IBM QRadar are affected by CVE-2021-20337?
IBM QRadar SIEM versions 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA are affected by CVE-2021-20337.
How can an attacker exploit vulnerability CVE-2021-20337?
An attacker can exploit vulnerability CVE-2021-20337 by using weaker than expected cryptographic algorithms to decrypt highly sensitive information.
How can I mitigate vulnerability CVE-2021-20337?
To mitigate vulnerability CVE-2021-20337, update IBM QRadar SIEM to version 7.3.3 Patch 9 or higher, or version 7.4.3 GA Patch 4 or higher.