CVE-2020-4979: IBM Qradar Security Information And Event Manager
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.
Affected products
- IBM Qradar Security Information And Event Manager: from 7.3.0, before 7.3.3 (fixed in 7.3.3); from 7.4.0, before 7.4.2 (fixed in 7.4.2); version 7.3.3 only; version 7.4.2 only
Published 2021-05-05. Last modified 2026-06-17.