Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Qradar_security_information_and_event_manager
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 165 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-01-27 | CVE-2020-4789 | IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 189302. | Qradar_security_information_and_event_manager | 6.5 | ||
2021-01-27 | CVE-2020-4787 | IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 189224. | Qradar_security_information_and_event_manager | 2.3 | ||
2021-01-27 | CVE-2020-4786 | IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 189221. | Qradar_security_information_and_event_manager | 4.3 | ||
2020-11-05 | CVE-2018-1725 | IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclosure. IBM X-Force ID: 147440. | Qradar_security_information_and_event_manager | 2.3 | ||
2020-10-08 | CVE-2019-4545 | IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877. | Qradar_security_information_and_event_manager | 7.5 | ||
2019-01-29 | CVE-2018-1733 | IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811. | Qradar_security_information_and_event_manager | 5.3 | ||
2020-08-11 | CVE-2020-4486 | IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. IBM X-Force ID: 181861. | Qradar_security_information_and_event_manager | N/A | ||
2020-08-11 | CVE-2020-4485 | IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security mechanisms in future attacks. IBM X-Force ID: 181860. | Qradar_security_information_and_event_manager | N/A | ||
2020-07-14 | CVE-2020-4513 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182368. | Qradar_security_information_and_event_manager | N/A | ||
2020-07-14 | CVE-2020-4512 | IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands. | Qradar_security_information_and_event_manager | N/A |