← Back to browse · API

CVE-2020-4280

Severity
MEDIUM
CVSS
6.3
EPSS
0.73451
Risk score
50.91
CISA KEV
No
PoC
No
Published
2020-10-08
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-25527, GHSA-M56G-8MXC-8694
Products
IBM:QRadar SIEM 7.3.0, IBM:QRadar SIEM 7.3.3.Patch.4, IBM:QRadar SIEM 7.4.0, IBM:QRadar SIEM 7.4.1
Sources
euvd EUVD-2020-25527

Description

IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 176140.

References