← Back

CVE-2020-4787

nvd nist
Published: Jan 27, 2021Modified: Nov 21, 2024

JSON object

Loading...
2.3
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 0.8 / Impact: 1.4
Source: NVD

Description

IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 189224.

Affected (26)

1 product
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.3.0
Version 7.3.1
Version 7.3.1 p3
Version 7.3.1 p4
Version 7.3.1 p5
Version 7.3.1 p6
Version 7.3.2
Version 7.3.2 interim_fix_01
Version 7.3.2 interim_fix_02
Version 7.3.2 p1
Version 7.3.2 p2
Version 7.3.2 p3
Version 7.3.2 p4
Version 7.3.3
Version 7.3.3 p1
Version 7.3.3 p2
Version 7.3.3 p3
Version 7.3.3 p4
Version 7.3.3 p5
Version 7.4.0
Version 7.4.0 p1
Version 7.4.0 p2
Version 7.4.1
Version 7.4.1 patch1
Version 7.4.2
Version 7.4.2 p1

References (4)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.