Remote Information Disclosure in IBM QRadar Network Security Products
CVE-2020-4160

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 November 2021

Summary

The vulnerability in IBM QRadar Network Security versions 5.4.0 and 5.5.0 arises from an improper configuration of HTTP Strict Transport Security. This misconfiguration could enable a remote attacker to leverage man-in-the-middle techniques to gain unauthorized access to sensitive information. As a result, organizations using affected versions are advised to apply patches and ensure that the proper security measures are in place to mitigate potential risks associated with this exposure.

Affected Version(s)

QRadar Network Security 5.4.0

QRadar Network Security 5.5.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.