
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM QRadar SIEM versions 7.3 and 7.4 were identified as vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. The vulnerability, tracked as CVE-2020-5013, was publicly disclosed and addressed by IBM in April 2021. The affected versions include IBM QRadar 7.3.0 to 7.3.3 Patch 7 and IBM QRadar 7.4.0 to 7.4.2 Patch 2 (IBM Security Bulletin).
The vulnerability received a CVSS Base score of 7.1 with a vector of CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L, indicating a high severity issue. The vulnerability specifically relates to the XML data processing functionality in QRadar SIEM, where improper handling of XML external entities could lead to security implications (IBM Security Bulletin).
The exploitation of this vulnerability could allow a remote attacker to expose sensitive information or consume memory resources in the affected systems. The high confidentiality impact rating in the CVSS score suggests significant potential for information disclosure (IBM Security Bulletin).
The vulnerability requires network access and low privilege levels for exploitation, as indicated by the CVSS vector (AV:N/AC:L/PR:L). The attack complexity is rated as low, suggesting that the vulnerability is relatively straightforward to exploit if access conditions are met (IBM Security Bulletin).
IBM released patches to address this vulnerability: QRadar/QRM/QVM/QRIF/QNI 7.3.3 Patch 8 and QRadar/QRM/QVM/QRIF/QNI 7.4.2 Patch 3. No workarounds or alternative mitigations were provided by IBM, making patch installation the only recommended solution (IBM Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."