CVE-2020-4980

EUVD-2020-26227
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ibmCNA
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.0/C:H/A:N/AC:H/UI:N/I:N/S:U/PR:N/AV:A/E:U/RC:C/RL:O
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.3.0 ≤
𝑥
< 7.3.3
ibmqradar_security_information_and_event_manager
7.4.0 ≤
𝑥
< 7.4.3
ibmqradar_security_information_and_event_manager
7.3.3
ibmqradar_security_information_and_event_manager
7.3.3:p1
ibmqradar_security_information_and_event_manager
7.3.3:p2
ibmqradar_security_information_and_event_manager
7.3.3:p3
ibmqradar_security_information_and_event_manager
7.3.3:p4
ibmqradar_security_information_and_event_manager
7.3.3:p5
ibmqradar_security_information_and_event_manager
7.3.3:p6
ibmqradar_security_information_and_event_manager
7.3.3:p7
ibmqradar_security_information_and_event_manager
7.4.3
𝑥
= Vulnerable software versions