CVE-2020-4993: IBM Qradar Security Information And Event Manager

Medium severity, CVSS 4.9. EPSS: 1.3% chance of exploitation in the next 30 days.

IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.

Affected products

  • IBM Qradar Security Information And Event Manager: from 7.3.0, before 7.3.3 (fixed in 7.3.3); from 7.4.0, before 7.4.2 (fixed in 7.4.2); version 7.3.3 only; version 7.4.2 only

Published 2021-05-05. Last modified 2026-06-17.