CVE-2020-4980
Summary
| CVE | CVE-2020-4980 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-16 17:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539. |
Risk And Classification
Problem Types: CWE-312 | CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Qradar Security Information And Event Manager | All | All | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | - | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | p1 | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | p2 | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | p3 | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | p4 | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | p5 | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | p6 | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.3.3 | p7 | All | All |
| Application | Ibm | Qradar Security Information And Event Manager | 7.4.3 | - | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM QRadar SIEM uses less secure methods for securing data at rest and in transit between hosts (CVE-2020-4980) | CONFIRM | www.ibm.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.