← Back to browse · API

CVE-2020-4888

Severity
MEDIUM
CVSS
6.3
EPSS
0.61964
Risk score
46.89
CISA KEV
No
PoC
No
Published
2021-01-28
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2020-26135, GHSA-Q3RG-74F5-F285
Products
IBM:QRadar SIEM 7.3, IBM:QRadar SIEM 7.3.3.Patch.7, IBM:QRadar SIEM 7.4, IBM:QRadar SIEM 7.4.2.Patch.1
Sources
euvd EUVD-2020-26135

Description

IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 190912.

References