=========================================================================== ZMCIRT Vulnerability Bulletin ZMC-2021.07.16.0810 QRadar SIEM: Access confidential data - Remote/unauthenticated 16th July 2021 =========================================================================== Product: QRadar SIEM Publisher: IBM Operating System: Linux variants Impact/Access: Access Confidential Data -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2020-4980 Original Bulletin: https://www.ibm.com/support/pages/node/6472891 - --------------------------BEGIN INCLUDED TEXT-------------------- IBM QRadar SIEM uses less secure methods for securing data at rest and in transit between hosts (CVE-2020-4980) Document Information Document number : 6472891 Modified date : 15 July 2021 Product : IBM QRadar SIEM Software version : 7.3, 7.4 Operating system(s): Linux Summary IBM QRadar SIEM uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. Vulnerability Details CVEID: CVE-2020-4980 DESCRIPTION: IBM QRadar SIEM uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. CVSS Base score: 5.3 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/ 192539 for the current score. CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) Affected Products and Versions IBM QRadar 7.3.0 to 7.3.3 Patch 7 IBM QRadar 7.4.0 to 7.4.3 GA Remediation/Fixes QRadar / QRM / QVM / QRIF / QNI 7.3.3 Patch 8 QRadar / QRM / QVM / QRIF / QNI 7.4.3 Patch 1 Workarounds and Mitigations None Change History 15 Jul 2021: Initial Publication ZMCIRT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. ZMCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Internet Email: report@cirt.zm Telephone: 7070 ZMCIRT personnel answer during Zambian business hours which are 8am to 5pm. On call after hours for member emergencies only. ===========================================================================
Copyright @2023 ZAMBIA CIRT