CVE-2020-4786
Last modified
CVE-2020-4786 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 189221.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Qradar Security Information And Event Manager | 7.3.0 |
| Ibm | Qradar Security Information And Event Manager | 7.3.1 |
| Ibm | Qradar Security Information And Event Manager | 7.3.2 |
| Ibm | Qradar Security Information And Event Manager | 7.3.3 |
| Ibm | Qradar Security Information And Event Manager | 7.4.0 |
| Ibm | Qradar Security Information And Event Manager | 7.4.1 |
| Ibm | Qradar Security Information And Event Manager | 7.4.2 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/189221VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6408866Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/189221VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6408866Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-4786?
How severe is CVE-2020-4786?
How do I fix CVE-2020-4786?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-4779A HTTP Verb Tampering vulnerability may impact IBM Curam Soc…8.1
- CVE-2020-4780OOTB build scripts does not set the secure attribute on sess…5.3
- CVE-2020-4781An improper input validation before calling java readLine() …6.5
- CVE-2020-4782IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 coul…6.5
- CVE-2020-4783IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow …5.9
- CVE-2020-4785IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1,…5.4
- CVE-2020-4787IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Pa…2.3
- CVE-2020-4788IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could all…4.7
- CVE-2020-4789IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Pa…6.5
- CVE-2020-4790IBM Security Identity Governance and Intelligence 5.2.6 coul…6.5
- CVE-2020-4791IBM Security Identity Governance and Intelligence 5.2.6 coul…5.3
- CVE-2020-4792IBM Edge 4.2 is vulnerable to cross-site scripting. This vul…5.4
Are you affected by CVE-2020-4786?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
