CVE-2021-20399: XEE
IBM QRadar is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20399?
CVE-2021-20399 is a vulnerability in IBM QRadar that allows for XML External Entity Injection (XXE) attacks, which can expose sensitive information or consume memory resources.
Which versions of IBM QRadar are affected by CVE-2021-20399?
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA are affected by CVE-2021-20399.
How severe is CVE-2021-20399?
CVE-2021-20399 has a severity rating of 9.1 (critical).
How can I fix CVE-2021-20399 in IBM QRadar?
To fix CVE-2021-20399 in IBM QRadar, you should apply the necessary patches or updates provided by IBM.
Where can I find more information about CVE-2021-20399?
More information about CVE-2021-20399 can be found on the IBM X-Force ID: 196073 page and IBM's support website.