
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM QRadar SIEM versions 7.3.0 to 7.3.3 Patch 3 and 7.4.0 to 7.4.0 Patch 2 were found to contain a vulnerability that could allow an authenticated user to cause a denial of service of the qflow process. The vulnerability, identified as CVE-2020-4511, was disclosed on July 13, 2020 (IBM Security).
The vulnerability occurs when an authenticated user sends a malformed sflow command to the system, which can result in the disruption of the qflow process. The vulnerability has been assigned a CVSS Base score of 6.5 with a vector of CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a network-accessible vulnerability requiring low attack complexity and low privileges, with no user interaction needed (IBM Security).
The successful exploitation of this vulnerability results in a denial of service condition affecting the qflow process in IBM QRadar SIEM. This can potentially disrupt the normal operation of the security information and event management system (IBM Security).
The vulnerability requires an authenticated user to exploit, suggesting a lower risk profile as it cannot be exploited by anonymous attackers. The attack can be executed remotely over the network with low attack complexity (IBM Security).
IBM has released patches to address this vulnerability. Users should upgrade to QRadar/QRM/QVM/QRIF/QNI 7.4.0 Patch 3 for version 7.4 systems, or QRadar/QRM/QVM/QRIF/QNI 7.3.3 Patch 4 for version 7.3 systems. No workarounds or alternative mitigations are available (IBM Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."