CVE-2020-4510: IBM Qradar Security Information And Event Manager

Medium severity, CVSS 5.5. EPSS: 2% chance of exploitation in the next 30 days.

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182365.

Affected products

  • IBM Qradar Security Information And Event Manager: from 7.3.0, up to and including 7.3.2; version 7.3.3 only; version 7.4.0 only

Published 2020-07-14. Last modified 2026-06-17.