CVE-2020-4979

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ibmCNA
7.5 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.0/C:H/PR:N/AV:A/AC:H/UI:N/I:H/S:U/A:H/RC:C/E:U/RL:O
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.3.0 ≤
𝑥
< 7.3.3
ibmqradar_security_information_and_event_manager
7.4.0 ≤
𝑥
< 7.4.2
ibmqradar_security_information_and_event_manager
7.3.3
ibmqradar_security_information_and_event_manager
7.3.3:fix_pack_1
ibmqradar_security_information_and_event_manager
7.3.3:fix_pack_2
ibmqradar_security_information_and_event_manager
7.3.3:fix_pack_3
ibmqradar_security_information_and_event_manager
7.3.3:fix_pack_4
ibmqradar_security_information_and_event_manager
7.3.3:fix_pack_5
ibmqradar_security_information_and_event_manager
7.3.3:fix_pack_6
ibmqradar_security_information_and_event_manager
7.3.3:fix_pack_7
ibmqradar_security_information_and_event_manager
7.4.2
ibmqradar_security_information_and_event_manager
7.4.2:fix_pack_1
ibmqradar_security_information_and_event_manager
7.4.2:fix_pack_2
𝑥
= Vulnerable software versions