Required CVE Record Information
Description
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.4 | MEDIUM | 3.0 | CVSS:3.0/PR:L/AC:L/UI:N/AV:N/C:L/I:L/S:U/A:N/E:U/RL:O/RC:C |
Product Status
Learn moreVersions 1 Total
Default Status: unknown
affected
Versions 1 Total
Default Status: unknown
affected
References 4 Total
- https://www.ibm.com/support/pages/node/6189705
- exchange.xforce.ibmcloud.com: ibm-qradar-cve20204274-auth-bypass (175980) vdb-entry
- seclists.org: 20200421 Authorization bypass in QRadar Forensics web application mailing-list
- http://packetstormsecurity.com/files/157338/QRadar-Community-Edition-7.3.1.6-Authorization-Bypass.html
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://www.ibm.com/support/pages/node/6189705 x_transferred
- exchange.xforce.ibmcloud.com: ibm-qradar-cve20204274-auth-bypass (175980) vdb-entryx_transferred
- seclists.org: 20200421 Authorization bypass in QRadar Forensics web application mailing-listx_transferred
- http://packetstormsecurity.com/files/157338/QRadar-Community-Edition-7.3.1.6-Authorization-Bypass.html x_transferred