CVE-2021-20400: Weak Encryption
IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.
Other sources
IBM QRadar uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-20400.
What is the severity of CVE-2021-20400?
The severity of CVE-2021-20400 is high.
Which version of IBM QRadar is affected by CVE-2021-20400?
IBM QRadar SIEM versions 7.3.0 to 7.3.3 and versions 7.4.0 to 7.4.3 are affected by CVE-2021-20400.
How can an attacker exploit CVE-2021-20400?
An attacker can exploit CVE-2021-20400 by using weaker than expected cryptographic algorithms to decrypt highly sensitive information.
Is there a fix for CVE-2021-20400?
Yes, IBM has released fixes for CVE-2021-20400. Please refer to the IBM support page for more information on specific versions and fix packs.