CVE-2020-4980

IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ibmCNA
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.0/C:H/A:N/AC:H/UI:N/I:N/S:U/PR:N/AV:A/E:U/RC:C/RL:O
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.3.0 ≤
𝑥
< 7.3.3
ibmqradar_security_information_and_event_manager
7.4.0 ≤
𝑥
< 7.4.3
ibmqradar_security_information_and_event_manager
7.3.3
ibmqradar_security_information_and_event_manager
7.3.3:p1
ibmqradar_security_information_and_event_manager
7.3.3:p2
ibmqradar_security_information_and_event_manager
7.3.3:p3
ibmqradar_security_information_and_event_manager
7.3.3:p4
ibmqradar_security_information_and_event_manager
7.3.3:p5
ibmqradar_security_information_and_event_manager
7.3.3:p6
ibmqradar_security_information_and_event_manager
7.3.3:p7
ibmqradar_security_information_and_event_manager
7.4.3
𝑥
= Vulnerable software versions