CVE Vulnerabilities

CVE-2020-4980

Cleartext Storage of Sensitive Information

Published: Jul 16, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
Qradar_security_information_and_event_managerIbm7.3.0 (including)7.3.3 (excluding)
Qradar_security_information_and_event_managerIbm7.4.0 (including)7.4.3 (excluding)
Qradar_security_information_and_event_managerIbm7.3.3 (including)7.3.3 (including)
Qradar_security_information_and_event_managerIbm7.3.3-p1 (including)7.3.3-p1 (including)
Qradar_security_information_and_event_managerIbm7.3.3-p2 (including)7.3.3-p2 (including)
Qradar_security_information_and_event_managerIbm7.3.3-p3 (including)7.3.3-p3 (including)
Qradar_security_information_and_event_managerIbm7.3.3-p4 (including)7.3.3-p4 (including)
Qradar_security_information_and_event_managerIbm7.3.3-p5 (including)7.3.3-p5 (including)
Qradar_security_information_and_event_managerIbm7.3.3-p6 (including)7.3.3-p6 (including)
Qradar_security_information_and_event_managerIbm7.3.3-p7 (including)7.3.3-p7 (including)
Qradar_security_information_and_event_managerIbm7.4.3 (including)7.4.3 (including)

Potential Mitigations

References